- Guardio Labs found CVE-2026-48294 in the Adobe Acrobat Chrome extension, allowing cross-site data disclosure
- Attackers could steal WhatsApp web chats if victims opened malicious landing pages with the extension active
- Adobe fixed the bug in version 26.7.2.0; Recommended update for 314M extension users
If you have the Adobe Acrobat extension for Chrome and like to chat over WhatsApp Web, there is a potential security vulnerability that you may want to address.
Security researchers at Guardio Labs discovered a “Universal Cross-Site Scripting (UXSS) class cross-origin data disclosure vulnerability,” which is another way of saying that a website could use the flaw to read content from a different website, loaded in a separate tab.
The vulnerability was found in the Adobe Acrobat Chrome extension and is now tracked as CVE-2026-48294. It was assigned a severity score of 7.4/10 (high) and affects versions 26.5.2.2 and earlier. Guardio Labs nicknamed it “HermeticReader” so it explodes.
“Insultingly ordinary” setup
The extension comes with different integrations, such as Google Drive or, in this case, WhatsApp Web. The WhatsApp integration component, known internally as “Hermes”, is where the bug was found.
In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) you have WhatsApp loaded in a separate tab; and 3) opens the malicious homepage, it could activate the extension’s vulnerable code path and allow attackers to access everything the victim has on their WhatsApp.
Some sources argue that threat actors could use this vulnerability to obtain one-time passwords sent via WhatsApp.
“The setup is almost insultingly ordinary: an attacker-controlled page, designed to look like the type of page you reach through search results, marketing emails, etc.,” Guardio Labs wrote in its analysis.
“The visitor, who already has the Adobe Acrobat extension installed, opens that page. The page activates a dormant engine within the extension, arriving directly at WhatsApp Web. Seconds later, the rendered web view of WhatsApp – the chat list, contact names, messages, the profile name, the text of any conversation is open – all of WhatsApp in the hands of the attacker.”
Adobe has since publicly acknowledged the issue and thanked researchers at Guardio Labs for their help. Also fixed the issue in version 26.7.2.0 which is currently available for download. The extension has more than 314 million users.
Through Hacker News
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




