Description

Cybersecurity researchers from Guardio Labs disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294 and nicknamed HermeticReader. The vulnerability, rated CVSS 7.4, affects extension versions up to and including 26.5.2.2 and could allow malicious websites to bypass browser security controls and access cross-origin data. If successfully exploited, an attacker could potentially access information displayed in a victim's authenticated WhatsApp Web session, including chat lists, contact names, message previews, profile information, and visible conversation text. The issue was caused by a combination of weaknesses in the extension's handling of web content and its WhatsApp integration functionality. A malicious webpage could interact with vulnerable extension resources, activate the underlying integration engine, and communicate with a WhatsApp Web tab running in the victim's browser. The exploit could then manipulate WhatsApp Web's Document Object Model and use HTML form behavior to transfer rendered page content to an attacker-controlled server. The attack required user interaction, such as visiting a specially crafted or compromised webpage, but did not require malware installation or theft of login credentials. Users and organizations should ensure the Adobe Acrobat Chrome extension is updated to the latest patched version and verify that no vulnerable versions remain deployed across managed browsers. Security teams should monitor browser and endpoint telemetry for suspicious activity involving the Adobe Acrobat extension, unexpected interactions with WhatsApp Web, and connections to unknown external domains. Organizations should also encourage users to avoid suspicious links and compromised websites, maintain updated browsers and extensions, and apply security updates promptly to reduce the risk of exploitation.