#5
SecurityWeek
general
July 22, 2026 at 14:22 UTC
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
By Eduard Kovacs
AI Summary
A vulnerability in the Adobe Acrobat Chrome extension — which has approximately 300 million installs — allowed any malicious website to silently exfiltrate WhatsApp Web messages and contacts without user authentication. The attack required only that the target visit a crafted webpage, making it a low-friction mass-exploitation scenario. The flaw has been patched, but the scale of the affected browser extension base makes this a significant supply-chain-adjacent web security event.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →