Exploited in the wild WordPress web-app Joomla malware
Баг в расширении Adobe Acrobat для Chrome давал доступ к сообщениям и контактам WhatsApp
CVE Tools coverage
Researchers from Guardio Labs discovered a critical vulnerability in the Adobe Acrobat Chrome extension, installed over 329 million times, that could allow malicious websites to access WhatsApp web session data without malware or password theft. The flaw, named HermeticReader and tracked as CVE-2026-48294 (CVSS score 7.4), is a Universal Cross-Site Scripting (UXSS) issue affecting all versions up to 26.5.2. Attackers could lure victims to a crafted webpage, which would exploit the vulnerable extension to bypass browser security policies and extract chat lists, contact names, message previews, and open conversation texts. A fix was included in version 26.5.2.3, distributed automatically.