logo

Adobe Acrobat WhatsApp Flaw “HermeticReader”

ID: 700dc1d3-7e27-53f0-87d1-34cd9ff924a4

STIX ID: report--700dc1d3-7e27-53f0-87d1-34cd9ff924a4

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2026-07-23

Date Updated: 2026-07-25

Author: ameer

...
...

Adobe Acrobat's Hermes-based WhatsApp integration contained a universal cross-site scripting flaw dubbed "HermeticReader" (CVE-2026-48294, CVSS 7.4) that could let a malicious webpage bypass browser boundaries and exfiltrate WhatsApp Web session contents; the issue affected versions up to 26.5.2.2 across an estimated 329 million browsers, was patched in version 26.5.2.3 with no observed active exploitation, and organizations are advised to verify extension versions, update or remove unnecessary extensions, and review managed browser update policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.