A malicious Chrome extension for Adobe Acrobat could allow hackers to access private WhatsApp chats



  • Guardio Labs found CVE-2026-48294 in the Adobe Acrobat Chrome extension, allowing cross-site data disclosure
  • Attackers could steal WhatsApp web chats if victims opened malicious landing pages with the extension active
  • Adobe fixed the bug in version 26.7.2.0; Recommended update for 314M extension users

If you have the Adobe Acrobat extension for Chrome and like to chat over WhatsApp Web, there is a potential security vulnerability that you may want to address.

Security researchers at Guardio Labs discovered a “Universal Cross-Site Scripting (UXSS) class cross-origin data disclosure vulnerability,” which is another way of saying that a website could use the flaw to read content from a different website, loaded in a separate tab.

Leave a Comment

Your email address will not be published. Required fields are marked *