hacker-news · Crawled Jul 23, 2026
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
3 IoCs
Read original article ↗
AI Summary
A vulnerability chain dubbed HermeticReader in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294, allowed malicious websites to bypass the same-origin policy and steal data from WhatsApp Web sessions. The flaw exploited universal cross-site scripting (UXSS) to access session-bound content without requiring malware installation or credential theft. Attackers only needed to trick users into visiting a malicious page, which could silently extract WhatsApp chat lists, messages, contact names, and profile information.
AI-extracted · verify before operational use