Adobe patched a vulnerability in its Acrobat Chrome extension that allowed a malicious website to access private WhatsApp Web data from a victim’s browser. The issue, tracked as CVE-2026-48294 and dubbed HermeticReader by Guardio, affected extension version 26.5.2.1 and earlier and was fixed in 26.5.2.3. Researchers said the bug stemmed from missing security checks in the extension’s internal messaging system, creating a UXSS-class cross-origin data disclosure path in an extension installed in roughly 329 million browsers.
According to the reports, an attacker only needed to lure a user with the vulnerable extension installed to a malicious site; no malware, stolen credentials, WhatsApp flaw, session cookies, or extra clicks were required to extract rendered chat content. The attack could abuse Adobe’s dormant Hermes integration and privileged DOM access to scrape contact names, messages, conversations, and account details in plain text from an open WhatsApp tab. Researchers also warned the same capability could be used to replace WhatsApp’s device-linking QR code in a potential account hijack scenario, although that step would require the victim to scan the substituted code. Guardio said it found no evidence of active exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
After discovering the flaw, Guardio reported the HermeticReader vulnerability to Adobe. Adobe assigned the issue CVE-2026-48294.
Adobe patched the vulnerability in June by releasing version 26.5.2.3 of the Acrobat Chrome extension, fixing the issue present in version 26.5.2.1 and earlier. Researchers said they found no evidence of active exploitation.
Guardio identified a UXSS-class vulnerability chain in the Adobe Acrobat Chrome extension, dubbed HermeticReader and tracked as CVE-2026-48294, that could let a malicious website access rendered WhatsApp Web data. The issue affected extension version 26.5.2.1 and below and relied on missing security checks in the extension's internal messaging system.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourceguard.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.