logo

WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw

ID: 835a2add-8730-5e3e-a18d-30af46daa705

STIX ID: report--835a2add-8730-5e3e-a18d-30af46daa705

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

**HermeticReader (CVE-2026-48294)** is a vulnerability in the Adobe Acrobat Chrome extension that allowed a malicious website to bypass same-origin protections and silently exfiltrate WhatsApp Web chat lists and messages if the user had the vulnerable extension (<=26.5.2.2) installed and was logged into WhatsApp Web; Adobe patched it in version 26.5.2.3 and users are advised to update, remove untrusted extensions, and review linked WhatsApp devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.