- Guardio Labs found CVE‑2026‑48294 in the Adobe Acrobat Chrome extension, allowing cross-site data disclosure
- Attackers could steal WhatsApp web chats if victims opened malicious landing pages with an active extension
- Adobe fixed the flaw in version 26.7.2.0; recommended update for 314 million extension users
If you have the Adobe Acrobat extension for Chrome and like to chat via WhatsApp Web, there is a potential security vulnerability you may want to patch.
Security researchers at Guardio Labs discovered a “Universal Cross-Site Scripting (UXSS)-class cross-origin data disclosure vulnerability,” which is another way of saying that a website could use the flaw to read content from another website, loaded in a separate tab.
The vulnerability was found in the Adobe Acrobat Chrome extension and is now tracked as CVE-2026-48294. It received a severity score of 7.4/10 (high) and affects versions 26.5.2.2 and earlier. Guardio Labs has nicknamed it “HermeticReader” because of what it leverages.
“Insulting and ordinary” configuration
The extension comes with different integrations, like Google Drive or, in this case, WhatsApp Web. The WhatsApp integration component, known internally as “Hermes”, is where the bug was found.
In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) WhatsApp is loaded in a separate tab; and 3) opens the malicious landing page, this could trigger the extension’s vulnerable code path and allow attackers to access everything the victim has on their WhatsApp.
Some sources claim that malicious actors could use this vulnerability to extract one-time passcodes transmitted via WhatsApp.
“The setup is almost insultingly ordinary: an attacker-controlled page, dressed up to look like the type of page you land on through search results, marketing emails, etc.,” Guardio Labs wrote in its analysis.
“The visitor, who has already installed the Adobe Acrobat extension, opens this page. The page wakes up a dormant engine inside the extension, goes directly to WhatsApp Web. A few seconds later, the rendered WhatsApp web view – the chat list, contact names, messages, profile name, the text of any open conversations – all of WhatsApp in the hands of the attacker.”
Adobe has since publicly acknowledged the issue and thanked researchers at Guardio Labs for their help. It also fixed the issue with version 26.7.2.0 currently available for download. The extension has over 314 million users.
Via Hacker news
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




