Adobe Acrobat WhatsApp Flaw “HermeticReader”
ID: 700dc1d3-7e27-53f0-87d1-34cd9ff924a4
STIX ID: report--700dc1d3-7e27-53f0-87d1-34cd9ff924a4
Feed Name: SOCRadar Blog
Adobe Acrobat's Hermes-based WhatsApp integration contained a universal cross-site scripting flaw dubbed "HermeticReader" (CVE-2026-48294, CVSS 7.4) that could let a malicious webpage bypass browser boundaries and exfiltrate WhatsApp Web session contents; the issue affected versions up to 26.5.2.2 across an estimated 329 million browsers, was patched in version 26.5.2.3 with no observed active exploitation, and organizations are advised to verify extension versions, update or remove unnecessary extensions, and review managed browser update policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
