Home / Jul 23, 2026 / Story
0
#4 The Hacker News general July 22, 2026 at 15:01 UTC

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

By [email protected] (The Hacker News)

AI Summary

A now-patched vulnerability chain (CVE-2026-48294, CVSS 7.4) dubbed HermeticReader in the Adobe Acrobat Chrome extension — with over 314 million installs — allowed malicious websites to silently read a victim's WhatsApp Web messages and contacts without authentication. Discovered by Guardio Labs, exploitation required only luring the target to a malicious page. The scale of the affected user base makes this a high-impact supply-chain-adjacent browser extension risk.

Relevance score: 89.0/100

# More from July 23