Description
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and Moreen·The Hacker News· Research ai-ml
- Баг в расширении Adobe Acrobat для Chrome давал доступ к сообщениям и контактам WhatsAppru-ru·Хакер (xakep.ru)· Exploited WordPress web-app
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Dataen·The Hacker News· Patch Adobe data-breach
- Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theften-us·SecurityWeek· Research Adobe Acrobat Chrome extension web-app
- Adobe Chrome extension flaw let sites access private WhatsApp chatsen-us·BleepingComputer· Research Adobe Acrobat Chrome extension web-app
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-48294 and every CVE in our database. Create a free account — no credit card required.
Create Free Account