Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-48294

Adobe Acrobat Chrome extension cross-context WhatsApp data access (HermeticReader)

CVE-2026-48294: cross-context flaw in the Adobe Acrobat Chrome extension let any site silently read WhatsApp Web data. CVSS 7.4; patched by Adobe.

cat cve-2026-48294.json
Vendor
Adobe
Product
Adobe Acrobat Chrome Extension
CVSS
7.4
EPSS (exploit probability)
1.9%
Status
patched
Published

A vulnerability chain in the Adobe Acrobat Chrome extension — installed on over 314 million browsers — allowed any website to silently read WhatsApp Web conversations and data without user authentication or visible notification. Guardio Labs discovered and reported the flaw, naming the chain HermeticReader.

Mechanism: The Adobe Acrobat extension requests broad page-access permissions to detect and open PDF files. The HermeticReader chain exploited how those permissions were scoped across tab contexts, allowing a page in one context to initiate reads against data rendered in a separate WhatsApp Web session. The attack required no user interaction beyond having both the extension installed and WhatsApp Web open simultaneously.

Affected scope: All Adobe Acrobat Chrome extension versions prior to the patched build. The extension had more than 314 million installs at time of disclosure.

Impact: Silent access to WhatsApp Web conversations, contacts, and media as rendered in the browser’s decrypted view. No bypass of WhatsApp’s end-to-end encrypted transport — the exposure was at the rendering layer.

Remediation: Adobe has patched the vulnerability. Update the Adobe Acrobat extension to the current version via the Chrome Web Store. Users who disabled the extension pending a fix may re-enable the updated version. See the NVD record for CVE-2026-48294 and full coverage at Adobe Acrobat Extension Let Sites Read WhatsApp Chats.

Sources: NVD — CVE-2026-48294 | The Hacker News / Guardio Labs, July 22, 2026 | BleepingComputer, July 22, 2026