Adobe Acrobat Extension Vulnerability Enables WhatsApp Data Theft

Adobe Acrobat Extension Vulnerability Enables WhatsApp Data Theft

First seen 22 Jul 2026, 15:26 UTC BleepingcomputerThehackernewsCybersecuritynewsFeeds.4SysopsSecurityaffairs.Co+2 85% similarity 70.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294 and named HermeticReader, allows attackers to access WhatsApp Web data without authentication. The flaw affects approximately 329 million users and requires only a single visit to a malicious webpage. Exploitation involves manipulating the extension's integration engine, Hermes, which can execute commands on WhatsApp Web through predictable Tab IDs. Guardio Labs discovered the vulnerability and demonstrated data theft by injecting forms into WhatsApp Web. Adobe has released a patch (version 26.5.2.3) to address the issue, and there are no indications of active exploitation. The vulnerability impacts all versions of the extension up to 26.5.2.2.

Key Points: • CVE-2026-48294 allows unauthorized access to WhatsApp Web data via Adobe Acrobat extension. • The vulnerability affects around 329 million users and requires only a visit to a malicious site. • Adobe has released a patch, and Guardio Labs reported no signs of active exploitation.

ThreatCluster AI

Timeline

2026-06-16
CVE-2026-48294 published
Adobe disclosed a critical vulnerability in the Acrobat Chrome extension affecting WhatsApp Web.
Guardio
2026-07-22
Adobe releases patch for vulnerability
Adobe released version 26.5.2.3 to fix the HermeticReader vulnerability affecting millions.
BleepingComputer
2026-07-22
Guardio Labs reports vulnerability details
Guardio Labs detailed the HermeticReader exploit chain and its implications for WhatsApp Web data security.
Guardio

Community

Browse all →