Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

A recent discovery by web and browser security firm Guardio has shed light on a serious vulnerability in Adobe’s popular Chrome extension, Acrobat. The exploit, dubbed HermeticReader, allowed attackers to silently steal users’ WhatsApp chats and contacts without their knowledge or consent.

The vulnerable extension, installed on approximately 329 million browsers, was found to have a UXSS-class cross-origin data disclosure vulnerability (CVE-2026-48294). This flaw enabled an attacker to trick the user into visiting a seemingly harmless webpage, which would then secretly write malicious code to the extension’s local storage. From there, the attacker could activate Hermes, Adobe’s dormant integration engine, allowing them to scrape WhatsApp Web for private chats, contacts, and account details in plain text.

What’s striking about this exploit is that it didn’t involve any malware deployment, compromised credentials, or access to the targeted device. The attack relied solely on social engineering, tricking users into loading a malicious webpage that would then interact with the vulnerable extension. This highlights the importance of being cautious when browsing online and avoiding suspicious links.

Adobe patched the vulnerability in June shortly after being informed of its existence by Guardio’s researchers. While the patch has since been applied to all affected extensions, it’s essential for users to keep their software up-to-date to prevent similar exploits in the future. It’s also crucial to remember that not all security breaches involve complex technical exploits; sometimes, a simple social engineering trick is enough for an attacker to gain access to sensitive information.

Guardio has published a video demonstrating the HermeticReader exploit in action, which serves as a stark reminder of the importance of staying vigilant when it comes to online security. By being aware of these types of attacks and taking proactive steps to protect ourselves, we can significantly reduce our risk of falling victim to similar exploits.

In light of this discovery, users are advised to review their installed browser extensions and ensure that they are running the latest versions. Regularly updating software is a critical aspect of maintaining online security, as it helps to prevent vulnerabilities like this one from being exploited by attackers. By taking these simple precautions, we can all do our part in staying safe online and protecting our sensitive information from falling into the wrong hands.


Source: SecurityWeek — 2026-07-22