CVE Tools
Back to feed
Exploited in the wild WordPress web-app Joomla malware

Баг в расширении Adobe Acrobat для Chrome давал доступ к сообщениям и контактам WhatsApp

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Researchers from Guardio Labs discovered a critical vulnerability in the Adobe Acrobat Chrome extension, installed over 329 million times, that could allow malicious websites to access WhatsApp web session data without malware or password theft. The flaw, named HermeticReader and tracked as CVE-2026-48294 (CVSS score 7.4), is a Universal Cross-Site Scripting (UXSS) issue affecting all versions up to 26.5.2. Attackers could lure victims to a crafted webpage, which would exploit the vulnerable extension to bypass browser security policies and extract chat lists, contact names, message previews, and open conversation texts. A fix was included in version 26.5.2.3, distributed automatically.