Adobe Chrome extension flaw let sites access private WhatsApp chats

A critical vulnerability in the Adobe Acrobat Chrome extension has left millions of users exposed, allowing malicious websites to access their private WhatsApp conversations without any form of authentication. This flaw, dubbed HermeticReader by researchers at Guardio, exploits a chain of vulnerabilities that can be triggered with just one visit to a compromised website.

The issue arises from the way the Adobe extension handles its integration with WhatsApp Web. The Hermes engine, which acts as an intermediary between Acrobat and WhatsApp, allows any website to redirect commands to the WhatsApp tab with a predictable Tab ID. This enables attackers to supply the ID to the extension, directing commands to the WhatsApp Web tab through a script that can manipulate the WhatsApp Document Object Model (DOM).

Guardio researchers demonstrated how this vulnerability can be exploited by injecting a form into WhatsApp Web and submitting it to an attacker-controlled server. The browser’s content security policy (CSP) reportedly lacked a form-action restriction, allowing the rendered page text to be sent to the attacker, exposing messaging data such as chat lists, contact names, messages, profile names, and conversation content.

What’s even more alarming is that this attack requires no session cookies, making it possible for malicious websites to access WhatsApp conversations without needing to authenticate themselves. However, it’s worth noting that messages that were not loaded or rendered are not leaked in the attack.

Researchers at Guardio have also highlighted another scenario where hackers can hijack WhatsApp accounts by leveraging the same DOM-control functionality. By replacing the device-linking QR code for WhatsApp with a substituted one, an attacker could take control of the user’s account – although this would require the victim to scan the substituted QR code, adding considerable friction.

Fortunately, Adobe has quickly responded to the vulnerability report and rolled out a patch within two days. The fix is available in version 26.5.2.3 of the Adobe Acrobat Chrome extension, which users are recommended to install immediately. According to Guardio Labs’ principal researcher, Nati Tal, there’s no indication of active exploitation for CVE-2026-48294.

To protect yourself from this vulnerability, it’s essential to verify that your Adobe Acrobat extension for Chrome is updated to the latest version (26.5.2.3). Users should also be cautious when visiting websites and avoid clicking on suspicious links or downloading attachments from unknown sources. By staying vigilant and keeping their software up-to-date, users can minimize the risk of falling victim to this type of attack.

As we’ve seen time and time again, security vulnerabilities like HermeticReader remind us that no system is completely secure. But with prompt action from vendors and responsible disclosure by researchers, the impact of these flaws can be significantly mitigated. By staying informed and taking proactive steps to protect ourselves, we can test every layer before attackers do – and stay one step ahead in the ongoing cat-and-mouse game between cybersecurity threats and defenses.


Source: Bleeping Computer — 2026-07-22