logo

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

ID: f21fb770-f6f9-5c0f-ba93-f9e34a4fb668

STIX ID: report--f21fb770-f6f9-5c0f-ba93-f9e34a4fb668

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Pierluigi Paganini

...
...

Guardio Labs disclosed a chained vulnerability (HermeticReader, CVE-2026-48294) in the Adobe Acrobat Chrome extension that allowed any attacker-controlled webpage to trigger the extension to inject commands into an open WhatsApp Web tab and exfiltrate chats, contacts, and message previews by abusing web-accessible extension pages, an unchecked service-worker message handler, and a feature-flag stored in extension local storage; Adobe acknowledged and patched the issue the same weekend and a CVE was issued.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.