Adobe Acrobat Extension Vulnerability Enables WhatsApp Data Theft
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294 and named HermeticReader, allows attackers to access WhatsApp Web data without authentication. The flaw affects approximately 329 million users and requires only a single visit to a malicious webpage. Exploitation involves manipulating the extension's integration engine, Hermes, which can execute commands on WhatsApp Web through predictable Tab IDs. Guardio Labs discovered the vulnerability and demonstrated data theft by injecting forms into WhatsApp Web. Adobe has released a patch (version 26.5.2.3) to address the issue, and there are no indications of active exploitation. The vulnerability impacts all versions of the extension up to 26.5.2.2.
Key Points: • CVE-2026-48294 allows unauthorized access to WhatsApp Web data via Adobe Acrobat extension. • The vulnerability affects around 329 million users and requires only a visit to a malicious site. • Adobe has released a patch, and Guardio Labs reported no signs of active exploitation.