CVE Tools
Back to feed
Patch released Adobe data-breach

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

A critical vulnerability in the Adobe Acrobat Chrome extension has been addressed following reports that it could allow attackers to silently access a user's WhatsApp Web session data. The flaw, named HermeticReader by Guardio Labs and tracked as CVE-2026-48294 (CVSS score: 7.4), is a universal cross-site scripting (UXSS) issue affecting all versions of the extension up to and including 26.5.2.2. Exploitation required user interaction but did not rely on phishing or malware installation—only visiting a maliciously crafted webpage was enough to trigger the attack. Attackers could use this to steal sensitive information such as chat lists, contact names, and message content from WhatsApp Web. Adobe has now issued a patch for the issue.