A critical vulnerability in Adobe's Acrobat PDF extension for Chrome, tracked as CVE-2026-48294, has been discovered, allowing malicious actors to intercept WhatsApp Web chats. The flaw, dubbed HermeticReader, was reported to Adobe in early June 2026 and promptly patched over a weekend. Researchers found that a single visit to a malicious website could compromise the extension, enabling it to silently spy on conversations. The exploit was platform-agnostic, affecting Windows, macOS, Linux, and ChromeOS devices that met specific conditions1. The vulnerability expanded the active attack surface, highlighting the need for users to prioritize patching based on their exposure and exploitation evidence. This matters to practitioners as it underscores the importance of promptly applying security updates to prevent potentially devastating breaches of sensitive information.
WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw
⚡ High Priority
Why This Matters
CVE-2026-48294 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- Malwarebytes Labs. (2026, July 23). WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw. *Malwarebytes*. https://www.malwarebytes.com/blog/bugs/2026/07/whatsapp-web-chats-exposed-by-adobes-acrobat-extension-flaw
Original Source
Malwarebytes Labs
Read original →