Adobe Chrome extension flaw let sites access private WhatsApp chats
ID: e48d489a-c447-52e2-9356-67bcb7b52e1f
STIX ID: report--e48d489a-c447-52e2-9356-67bcb7b52e1f
Feed Name: Bleeping Computer
Threat Score
**HermeticReader (CVE-2026-48294)** — A chain of vulnerabilities in the Adobe Acrobat Chrome extension allowed attacker-controlled webpages to impersonate extension messages, activate an integration engine (Hermes) and manipulate the WhatsApp Web DOM to exfiltrate rendered chat content (chat lists, contacts, messages, profile names); Adobe patched the issue in version 26.5.2.3 and Guardio observed no signs of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
