Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
ID: f3fa1189-4631-5db4-9c2c-df9ab85cff86
STIX ID: report--f3fa1189-4631-5db4-9c2c-df9ab85cff86
Feed Name: The Hacker News
Threat Score
Guardio Labs disclosed HermeticReader (CVE-2026-48294), a UXSS cross-origin data disclosure in the Adobe Acrobat Chrome extension (≤26.5.2.2) that allowed an attacker-controlled page to trigger the extension to read and POST rendered WhatsApp Web content (chat list, contacts, messages) to an attacker endpoint by abusing extension resources and HTML form submission behavior; the issue has been patched and carries a CVSS score of 7.4.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
