Adobe Acrobat Extension Flaw That Exposed WhatsApp Web Conversations
by Justin Erickson
Adobe has patched a vulnerability in its Acrobat PDF extension for Chrome that allowed a malicious website to access information displayed in a victim’s WhatsApp Web. The flaw is named HermeticReader, or CVE-2026-48294. All that is needed for an attack is three things: For the victim’s WhatsApp Web to be open or logged in, to have the vulnerable Acrobat extension installed, and for them to visit an attacker-controlled webpage: “…the chat list, contact names, messages, the profile name, the text of whatever conversation is open – the whole WhatsApp in the attacker’s hands.” The issue affected Acrobat extension versions 26.5.2.2 and earlier. Adobe fixed it in version 26.5.2.3, which was updated automatically through the Chrome Web Store. There was no evidence that the flaw was being actively exploited before the update was found.
Third-Party references:
Click the links below to learn more details. (Opens in a new tab/window.)
