bleeping-computer · Crawled Jul 22, 2026

Adobe Chrome extension flaw let sites access private WhatsApp chats

Read original article ↗

AI Summary

A vulnerability chain in the Adobe Acrobat Chrome extension, dubbed HermeticReader and tracked as CVE-2026-48294, allowed unauthenticated websites to access private WhatsApp Web chats by exploiting insecure message handling and DOM manipulation. Attackers could steal sensitive messaging data including contact names, messages, and profile information without requiring session cookies or user interaction beyond visiting a malicious page. The flaw also enabled potential account hijacking by replacing WhatsApp's device-linking QR code, though this would require user interaction to scan. Adobe patched the issue in version 26.5.2.3, and no active exploitation has been observed.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.