#4
The Hacker News
general
July 22, 2026 at 15:01 UTC
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
By [email protected] (The Hacker News)
AI Summary
A now-patched vulnerability chain (CVE-2026-48294, CVSS 7.4) dubbed HermeticReader in the Adobe Acrobat Chrome extension — with over 314 million installs — allowed malicious websites to silently read a victim's WhatsApp Web messages and contacts without authentication. Discovered by Guardio Labs, exploitation required only luring the target to a malicious page. The scale of the affected user base makes this a high-impact supply-chain-adjacent browser extension risk.
Relevance score: 89.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →