A serious security flaw was discovered in the Adobe Acrobat extension for Google Chrome that could allow malicious websites to access information displayed in WhatsApp Web. The issue did not affect WhatsApp’s end-to-end encryption directly, but instead abused the browser extension’s permissions. Security researchers from Guardio Labs named the attack HermeticReader and reported the problem to Adobe.

According to the researchers, the attack only required a victim to visit a specially crafted malicious website while the vulnerable Adobe Acrobat Chrome extension was installed. No login credentials, passwords, or authentication were needed for the attacker to trigger the exploit. The flaw relied on weaknesses in the extension’s internal communication system rather than in WhatsApp itself.
The vulnerability worked because the Adobe extension failed to properly verify where certain commands were coming from. A malicious website could send fake internal messages to the extension, activate its hidden WhatsApp integration, and redirect privileged actions to an open WhatsApp Web tab. This allowed attackers to interact with the page in ways that normal websites should never be able to.

Researchers explained that the extension contains an internal component called Hermes, which is designed to help Adobe Acrobat interact with WhatsApp Web for handling shared PDF files. By abusing this feature, attackers could manipulate the Document Object Model (DOM) of WhatsApp Web. This made it possible to access information already loaded and displayed inside the browser tab.
During their proof-of-concept demonstration, Guardio Labs successfully showed that attackers could collect visible chat data from WhatsApp Web. The exposed information included chat lists, contact names, profile names, conversation text, and other messages currently rendered on the screen. However, messages that had not yet been loaded or displayed could not be accessed using this technique.

The researchers also described another possible attack scenario involving WhatsApp account hijacking. By using the same browser control technique, an attacker could replace WhatsApp’s device-linking QR code with one belonging to the attacker. If the victim unknowingly scanned the fake QR code, their WhatsApp account could become linked to the attacker’s device. This attack, however, still required the victim to scan the substituted code.
The vulnerability has been assigned CVE-2026-48294 and affected Adobe Acrobat Chrome extension versions 26.5.2.1 and earlier. Guardio Labs said they found the flaw only a few hours after Adobe introduced it through an extension update. After receiving the responsible disclosure, Adobe responded quickly and released a fix within two days, preventing further risk for users.

Adobe has resolved the issue in version 26.5.2.3 of the Acrobat Chrome extension, which is being delivered automatically to users. Researchers stated that they found no evidence that the vulnerability had been actively exploited before the patch was released. Users are still advised to confirm that their Adobe Acrobat Chrome extension is updated to the latest version to ensure they remain protected from this security flaw.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news