logo

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

ID: f3fa1189-4631-5db4-9c2c-df9ab85cff86

STIX ID: report--f3fa1189-4631-5db4-9c2c-df9ab85cff86

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: [email protected] (The Hacker News)

...
...

Guardio Labs disclosed HermeticReader (CVE-2026-48294), a UXSS cross-origin data disclosure in the Adobe Acrobat Chrome extension (≤26.5.2.2) that allowed an attacker-controlled page to trigger the extension to read and POST rendered WhatsApp Web content (chat list, contacts, messages) to an attacker endpoint by abusing extension resources and HTML form submission behavior; the issue has been patched and carries a CVSS score of 7.4.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.