A critical vulnerability in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294, has been patched after it was found to allow malicious websites to silently hijack a user's WhatsApp Web data. The flaw, dubbed HermeticReader, affects over 314 million users and carries a CVSS score of 7.4, indicating a significant level of severity. If exploited, the vulnerability could grant attackers unauthorized access to sensitive information, highlighting the need for users to prioritize updates and patches based on their exposure and exploitation evidence1. The vulnerability expands the active attack surface, making it essential for users to take proactive measures to protect themselves. This vulnerability matters to practitioners as it underscores the importance of keeping extensions up to date, given the potential for malicious actors to exploit such flaws and compromise sensitive user data.