Adobe Acrobat Chrome extension cross-context WhatsApp data access (HermeticReader)
CVE-2026-48294: cross-context flaw in the Adobe Acrobat Chrome extension let any site silently read WhatsApp Web data. CVSS 7.4; patched by Adobe.
- Vendor
- Adobe
- Product
- Adobe Acrobat Chrome Extension
- CVSS
- 7.4
- EPSS (exploit probability)
- 1.9%
- Status
- patched
- Published
A vulnerability chain in the Adobe Acrobat Chrome extension — installed on over 314 million browsers — allowed any website to silently read WhatsApp Web conversations and data without user authentication or visible notification. Guardio Labs discovered and reported the flaw, naming the chain HermeticReader.
Mechanism: The Adobe Acrobat extension requests broad page-access permissions to detect and open PDF files. The HermeticReader chain exploited how those permissions were scoped across tab contexts, allowing a page in one context to initiate reads against data rendered in a separate WhatsApp Web session. The attack required no user interaction beyond having both the extension installed and WhatsApp Web open simultaneously.
Affected scope: All Adobe Acrobat Chrome extension versions prior to the patched build. The extension had more than 314 million installs at time of disclosure.
Impact: Silent access to WhatsApp Web conversations, contacts, and media as rendered in the browser’s decrypted view. No bypass of WhatsApp’s end-to-end encrypted transport — the exposure was at the rendering layer.
Remediation: Adobe has patched the vulnerability. Update the Adobe Acrobat extension to the current version via the Chrome Web Store. Users who disabled the extension pending a fix may re-enable the updated version. See the NVD record for CVE-2026-48294 and full coverage at Adobe Acrobat Extension Let Sites Read WhatsApp Chats.
Sources: NVD — CVE-2026-48294 | The Hacker News / Guardio Labs, July 22, 2026 | BleepingComputer, July 22, 2026
