Ethical Hacking News
A recently discovered vulnerability in the Adobe Acrobat Chrome extension has exposed over 329 million users to silent WhatsApp data theft. The bug, identified as CVE-2026-48294, allows attackers to steal sensitive information, including chats and contacts, from users who visit malicious websites without requiring any Adobe account or foothold on the machine.
The Adobe Acrobat Chrome extension has a vulnerability (CVE-2026-48294) that allows attackers to steal WhatsApp data.The bug was discovered by researcher Shaked Biner and leverages three separate flaws in the extension's internal messaging system.The extension is used by approximately 329 million browsers, making it one of the most widely used extensions in Chrome.Adobe quickly responded to the vulnerability by acknowledging, patching, and shipping a new version within a weekend.The incident highlights the importance of regular security audits and updates for browser extensions, as well as user caution when visiting unfamiliar websites.
The recent revelation about a vulnerability in the Adobe Acrobat Chrome extension has sent shockwaves throughout the cybersecurity community. The bug, identified as CVE-2026-48294, allows attackers to silently steal WhatsApp data, including chats, contacts, profile names, and message previews, from users who visit malicious websites. This exploit chain leverages three separate flaws in the extension's internal messaging system, demonstrating how a seemingly minor vulnerability can have far-reaching consequences.
The vulnerability is attributed to Guardio Labs researcher Shaked Biner, who discovered HermeticReader, a vulnerability chain that enabled any attacker-controlled webpage to silently steal WhatsApp data without requiring any Adobe account or foothold on the machine. The attack injects a POST form into WhatsApp's DOM, then uses an ELEMENT_OPERATION command to physically move WhatsApp's entire body node into the form's option element, effectively exfiltrating sensitive information.
The extension sits on roughly 329 million browsers, making it one of the most widely used extensions in Chrome. This highlights the importance of regular security audits and updates for browser extensions, as well as the need for users to be cautious when visiting unfamiliar websites.
Adobe quickly responded to the vulnerability by acknowledging, patching, and shipping a new version within the same weekend the report arrived. However, this incident serves as a reminder that the era in which a high-install extension could rely on nobody looking at the plumbing closely is ending, for defenders and attackers alike.
The structural lesson here isn't about any single clever trick but rather about the importance of thoroughly examining browser extensions and their internal workings. The fact that twelve individually unremarkable shortcuts in message passing, storage handling, feature flags, and host matching were combined into a chain that reached 329 million browsers underscores the need for constant vigilance in the cybersecurity landscape.
Related Information:
https://www.ethicalhackingnews.com/articles/Adobe-Acrobat-Chrome-Extension-Bug-Enables-Silent-WhatsApp-Data-Theft-A-Cautionary-Tale-of-Extensive-Vulnerability-ehn.shtml
https://securityaffairs.com/195805/hacking/adobe-acrobat-chrome-extension-bug-enabled-silent-whatsapp-data-theft.html
https://nvd.nist.gov/vuln/detail/CVE-2026-48294
https://www.cvedetails.com/cve/CVE-2026-48294/
Published: Wed Jul 22 17:28:54 2026 by llama3.2 3B Q4_K_M