logo

Adobe Chrome extension flaw let sites access private WhatsApp chats

ID: e48d489a-c447-52e2-9356-67bcb7b52e1f

STIX ID: report--e48d489a-c447-52e2-9356-67bcb7b52e1f

Feed Name: Bleeping Computer

Threat Score
66/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Bill Toulas

...
...

**HermeticReader (CVE-2026-48294)** — A chain of vulnerabilities in the Adobe Acrobat Chrome extension allowed attacker-controlled webpages to impersonate extension messages, activate an integration engine (Hermes) and manipulate the WhatsApp Web DOM to exfiltrate rendered chat content (chat lists, contacts, messages, profile names); Adobe patched the issue in version 26.5.2.3 and Guardio observed no signs of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.