Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

A highly popular Chrome extension made by Adobe was affected by a vulnerability that could have been exploited to silently steal a user’s WhatsApp chats and contacts.

According to web and browser security firm Guardio, whose researchers discovered and reported the vulnerability to Adobe, an attacker could have stolen users’ WhatsApp data simply by tricking them into visiting a seemingly harmless webpage.

The exploit did not involve a WhatsApp vulnerability, malware deployment, compromised credentials, or access to the targeted device.

The attack, dubbed HermeticReader, affected the Adobe Acrobat Chrome extension, which is installed in approximately 329 million browsers.

Adobe patched the vulnerability in June, shortly after being informed of its existence. The software giant assigned it CVE-2026-48294 and described it as a UXSS-class cross-origin data disclosure vulnerability.

Under the hood, the attack abuses a lack of security checks within the Adobe extension’s internal messaging system. When a victim loads...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE