Security Vulnerability Found in Adobe Acrobat Chrome Extension
A security vulnerability named "HermeticReader" has been discovered in Adobe Acrobat's Chrome browser extension, allowing attackers to access WhatsApp messages. Adobe has since fixed the issue.

A security vulnerability, dubbed "HermeticReader," has been identified in Adobe Acrobat's extension for the Chrome browser. Security firm Guardio Labs revealed that the exploit could allow attackers to steal users' WhatsApp chat logs and contact lists.
The vulnerability, assigned the identifier CVE-2026-48294 and a CVSS risk score of 7.4, was reported to Adobe in June. The company has since released a fix for the issue.
The attack chain required attackers to set up a malicious website capable of invoking the Acrobat Chrome extension. Upon a victim visiting the site, the extension would automatically run and access WhatsApp Web, enabling attackers to obtain chat lists, contact names, message content, and profile information.
Guardio Labs highlighted the flexibility of this attack method, noting that it did not require prior installation of malware on the victim's device. Simply causing a user to open a controlled static webpage could trigger the exploit.