A malicious Chrome extension for Adobe Acrobat could let hackers access private WhatsApp chats

https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg
  • Guardio Labs found CVE‑2026‑48294 in Adobe Acrobat Chrome extension, enabling cross‑site data disclosure
  • Attackers could steal WhatsApp Web chats if victims opened malicious landing pages with extension active
  • Adobe patched the flaw in version 26.7.2.0; update recommended for 314M extension users

If you have Adobe Acrobat’s extension for Chrome, and you like chatting through WhatsApp Web, there is a potential security vulnerability you might want to address.

Security researchers from Guardio Labs discovered a “universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability”, which is another way of saying that a website could use the flaw to read the contents of a different website, loaded in a separate tab.

The vulnerability was found in the Adobe Acrobat Chrome extension and is now tracked as CVE-2026-48294. It was given a severity score of 7.4/10 (high), and affects versions 26.5.2.2 and earlier. Guardio Labs dubbed it “HermeticReader” because of what it exploits.

"Insultingly...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more