hacker-news · Crawled Jul 23, 2026

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

3 IoCs
Read original article ↗

AI Summary

A vulnerability chain dubbed HermeticReader in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294, allowed malicious websites to bypass the same-origin policy and steal data from WhatsApp Web sessions. The flaw exploited universal cross-site scripting (UXSS) to access session-bound content without requiring malware installation or credential theft. Attackers only needed to trick users into visiting a malicious page, which could silently extract WhatsApp chat lists, messages, contact names, and profile information.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 185[.]141[.]63[.]137 Details →
Domain hermeticreader-test[.]com Details →
Domain whatsapp-data-capture[.]net Details →