A Vulnerability in Adobe’s Chrome Extension Exposed 300 Million Users to WhatsApp Data Theft
A critical vulnerability in a widely used Chrome extension has been patched by Adobe after researchers discovered it could be exploited to steal users’ WhatsApp chats, contacts, and account details. The flaw, known as HermeticReader, affected the Adobe Acrobat Chrome extension, which was installed on approximately 329 million browsers.
The attack worked by tricking victims into visiting a seemingly harmless webpage that contained hidden code. This code exploited a lack of security checks within the Adobe extension’s internal messaging system, allowing attackers to silently write to the extension’s local storage and activate Hermes, a dormant integration engine built by Adobe. Once activated, this engine bridged the gap to WhatsApp Web, enabling attackers to scrape private chats, contacts, and account details in plain text.
What makes this vulnerability particularly concerning is that it did not require any prior access or credentials from the targeted device. Users were at risk simply because they had installed the vulnerable extension on their browser. Fortunately, Adobe patched the issue shortly after being informed of its existence, assigning it the CVE-2026-48294 designation and describing it as a UXSS-class cross-origin data disclosure vulnerability.
The researchers who discovered the flaw, Guardio, have published a video demonstrating how an attack would work in practice. The exploit’s simplicity and effectiveness serve as a reminder that even seemingly innocuous extensions can pose significant security risks if not properly maintained or secured.
This incident highlights the importance of staying up-to-date with software patches and regularly reviewing installed extensions for potential vulnerabilities. It also underscores the need for developers to prioritize security in their products, ensuring that internal messaging systems and other components are robust against exploitation. By taking these precautions, users can significantly reduce their exposure to attacks like HermeticReader.
In this case, Adobe’s swift action in patching the vulnerability has mitigated the risk for millions of users. However, it serves as a timely reminder for all users to remain vigilant about security and keep their software and extensions up-to-date.
Source: SecurityWeek — 2026-07-22