A Critical Flaw in Adobe’s Chrome Extension Exposes Private WhatsApp Chats to Attackers
A recent discovery by cybersecurity firm Guardio has revealed a significant vulnerability in Adobe’s Acrobat extension for Chrome, allowing attackers to access and steal sensitive information from private WhatsApp chats. The flaw, dubbed HermeticReader, can be exploited without any form of authentication, making it a concerning issue for users who rely on the extension for various tasks.
The attack works by utilizing a chain of vulnerabilities (CVE-2026-48294) that enable an attacker to inject malicious code into the extension’s storage from any web page. This allows them to disguise commands as internal extension messages and redirect privileged operations into a WhatsApp tab with a predictable ID. The Hermes engine, which acts as an intermediary between Acrobat and WhatsApp, can then be exploited to send commands directly to the messaging service.
Guardio’s researchers demonstrated how this vulnerability can be used to steal sensitive information from WhatsApp chats, including conversation content, contact names, messages, profile name, and even chat lists. What’s more alarming is that no session cookies are required for the attack to succeed, making it a relatively straightforward process for an attacker to exploit.
In a particularly concerning scenario, hackers could leverage this vulnerability to hijack WhatsApp accounts by replacing the device-linking QR code with their own. While this would require some user interaction, such as scanning the substituted code, it adds considerable friction and increases the likelihood of successful exploitation.
Fortunately, Adobe has quickly patched the issue in version 26.5.2.3, which is now automatically available to users. However, it’s essential for users to verify that their extension is up-to-date to prevent potential exploitation. Guardio commended Adobe’s rapid response to the vulnerability report, acknowledging that the vendor’s swift action was crucial in preventing widespread exploitation.
This incident serves as a stark reminder of the importance of keeping software and extensions up-to-date, especially those with sensitive permissions like WhatsApp integration. It also highlights the need for vendors to prioritize security and rapidly respond to reported vulnerabilities. As users, it’s essential to remain vigilant and test every layer of our digital defenses before attackers do.
In this case, the fix is simple: ensure your Adobe Acrobat extension for Chrome is updated to version 26.5.2.3. By doing so, you’ll be protecting yourself from a potentially devastating attack that could compromise sensitive information.
Source: Bleeping Computer — 2026-07-22