Adobe Patches Acrobat Extension Flaw Exposing WhatsApp Data
Adobe Acrobat’s Chrome extension lets users work with PDF files in the browser, but its broad installation base and page-access privileges can magnify security failures beyond documents. Guardio Labs dubbed the flaw HermeticReader, tracked as CVE-2026-48294. The vulnerability is significant because a hostile website could turn a trusted browser add-on into a conduit for reaching data in another web service, exposing communications that users would normally expect to remain isolated.
Guardio Labs said AI-assisted analysis uncovered the attack path in just four hours. An attacker could lure a user to a malicious webpage and silently exploit the Acrobat extension to extract WhatsApp chat histories and contact information without the victim’s knowledge. Adobe issued a patch in 2026 to close the vulnerability. Users should update the extension promptly; the available information did not specify how many people were affected or whether the flaw had been exploited in active attacks.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.