Adobe: Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users

Adobe: Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users

Adobe Acrobat Chrome Extension Flaw Exposed WhatsApp Web Data in Silent Attack

Security researchers at Guardio Labs uncovered a critical vulnerability in the Adobe Acrobat PDF Extension for Chrome, tracked as CVE-2026-48294 (CVSS 7.4), which allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from users who merely visited a malicious webpage without requiring clicks, downloads, or credential theft.

Dubbed "HermeticReader", the flaw was a universal cross-site scripting (UXSS) issue that bypassed Chrome’s same-origin policy, enabling attackers to read data from an active WhatsApp Web session in another tab. The vulnerability affected all versions of the extension up to 26.5.2.2, which was installed on 314–329 million browsers worldwide.

How the Attack Worked

  1. Initial Exploitation: A victim with the vulnerable extension lands on an attacker-controlled webpage.
  2. Forged Messaging: A hidden iframe exploited the extension’s web-accessible resources to send unverified commands to its background service worker.
  3. Feature Flag Activation: Attackers manipulated local storage to enable "Hermes", Adobe’s dormant WhatsApp Web integration engine.
  4. Tab Hijacking: The malicious page predicted WhatsApp Web’s tab ID using Chrome’s sequential numbering system.
  5. DOM Manipulation: The attacker injected a hidden form into WhatsApp Web, relocating live chat content into it.
  6. Data Exfiltration: Submitting the form sent rendered chat text, contact names, and message previews to the attacker’s server all without triggering security warnings.

The attack exploited weak form-action restrictions in WhatsApp Web’s content security policy, allowing cross-origin data submission.

Response & Impact

Adobe acknowledged and patched the flaw within a weekend, releasing version 26.5.2.3 via the Chrome Web Store. The fix was automatically deployed, though users were advised to verify their extension version.

The incident highlights a growing risk in browser extensions with massive install bases, where seemingly minor flaws in message-passing, storage validation, and feature-flag logic can chain into full account compromise. As extensions increasingly integrate with messaging platforms, unvetted "plumbing" code is becoming a critical attack surface.

Source: https://cybersecuritynews.com/acrobat-extension-flaw-whatsapp-chats/

Adobe Acrobat cybersecurity rating report: https://www.rankiteo.com/company/adobe-acrobat

"id": "ADO1784744632",
"linkid": "adobe-acrobat",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '314–329 million browsers '
                                              'worldwide',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Adobe',
                        'size': 'Large',
                        'type': 'Software Company'},
                       {'customers_affected': 'Users with active WhatsApp Web '
                                              'sessions',
                        'location': 'Global',
                        'name': 'WhatsApp Web Users',
                        'type': 'End Users'}],
 'attack_vector': 'Browser Extension Vulnerability (UXSS)',
 'customer_advisories': 'Users advised to verify their Adobe Acrobat PDF '
                        'Extension for Chrome version and update if necessary.',
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, private communications)',
                 'type_of_data_compromised': ['WhatsApp Web chats',
                                              'Contacts',
                                              'Profile data',
                                              'Message previews']},
 'description': 'Security researchers at Guardio Labs uncovered a critical '
                'vulnerability in the Adobe Acrobat PDF Extension for Chrome '
                '(CVE-2026-48294, CVSS 7.4) that allowed attackers to silently '
                'harvest WhatsApp Web chats, contacts, and profile data from '
                'users who merely visited a malicious webpage without '
                'requiring clicks, downloads, or credential theft. The flaw '
                'was a universal cross-site scripting (UXSS) issue that '
                'bypassed Chrome’s same-origin policy, enabling attackers to '
                'read data from an active WhatsApp Web session in another tab.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'silent data harvesting',
            'data_compromised': 'WhatsApp Web chats, contacts, profile data, '
                                'message previews',
            'identity_theft_risk': 'High (exposure of personally identifiable '
                                   'information)',
            'systems_affected': 'Adobe Acrobat PDF Extension for Chrome '
                                '(versions up to 26.5.2.2)'},
 'investigation_status': 'Resolved (patched)',
 'lessons_learned': 'The incident highlights risks in browser extensions with '
                    'massive install bases, where minor flaws in '
                    'message-passing, storage validation, and feature-flag '
                    'logic can chain into full account compromise. Unvetted '
                    "'plumbing' code in extensions integrating with messaging "
                    'platforms is a critical attack surface.',
 'post_incident_analysis': {'corrective_actions': ['Patch released to fix UXSS '
                                                   'vulnerability',
                                                   'Automatic update '
                                                   'deployment via Chrome Web '
                                                   'Store',
                                                   'User advisories to verify '
                                                   'extension version'],
                            'root_causes': ['Weak form-action restrictions in '
                                            'WhatsApp Web’s content security '
                                            'policy',
                                            'UXSS vulnerability in Adobe '
                                            'Acrobat PDF Extension',
                                            'Predictable tab ID enumeration in '
                                            'Chrome',
                                            'Unverified message-passing in '
                                            'extension background service '
                                            'worker']},
 'recommendations': 'Verify browser extension versions, audit extension '
                    'permissions, and monitor for unusual behavior in '
                    'integrated services like WhatsApp Web.',
 'references': [{'source': 'Guardio Labs'}],
 'response': {'containment_measures': 'Adobe released a patch (version '
                                      '26.5.2.3) via Chrome Web Store',
              'remediation_measures': 'Automatic deployment of patched '
                                      'extension version; users advised to '
                                      'verify extension version',
              'third_party_assistance': 'Guardio Labs (security researchers)'},
 'title': 'Adobe Acrobat Chrome Extension Flaw Exposed WhatsApp Web Data in '
          'Silent Attack',
 'type': 'Data Breach',
 'vulnerability_exploited': 'CVE-2026-48294 (Universal Cross-Site Scripting - '
                            'UXSS)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.