A chain of vulnerabilities in the Adobe Acrobat extension for Chrome has turned this PDF document management solution into a tool to extract WhatsApp Web user conversations.
The cybersecurity company Guardio Labs has shared the findings of a chain of vulnerabilities already corrected, registered as CVE-2026-48294, which has put the privacy of WhatsApp users at risk with a single click.
Specifically, it targets WhatsApp Web users with the Adobe Acrobat extension installed in the Chrome browser, who, by entering a malicious web page, give attackers access to their conversation history, contacts and other private information without realizing it.
To achieve this, the vulnerability, called HermeticReader, takes advantage of a series of localized flaws in the way the extension communicates and manages data, starting with the fact that when web pages load some of their parts with hidden frames (iframes), the origin of the information is not properly verified.
This allows attackers to write commands to the internal storage of the Adobe extension, access that activates an internal engine known as Hermes, responsible for integration with WhatsApp Web.
For the attack to work, it requires a malicious web page posing as a Google search result, which tricks the extension into giving it the identifier of the browser tab where WhatsApp Web is open.
With Hermes activated and the identifier, and taking advantage of the privileged permissions that the Adobe extension has, the attacker can silently inject code directly into the victim’s WhatsApp Web window. This allows you to read, copy and send to a server under your control everything that appears on the screen.
As reported by Guardio Labs, this chain of vulnerabilities affects the Adobe Acrobat extension for Chrome up to version 26.5.2.1, since the one released as v26.5.2.3 includes the correction.
Likewise, they have highlighted the role of artificial intelligence agents to monitor browser extensions and quickly detect errors that may put user security at risk. They claim that with this automated system they identified the problem only four hours after Adobe distributed the affected update.
Guardio Labs has also appreciated the speed of Adobe, which after receiving the report, took two days to share the patch that corrects the vulnerability.
Land O’ Lakes, FL Professional Tree Removal Services | LandOLakesLandscaping.us
Lutz, FL Landscaping Services | LutzLandscaping.us
Lutz, FL Professional Gardening Services | LutzLandscaping.us
Lutz, FL Professional Brush Removal Services | LutzLandscaping.us
Lutz, FL Professional Flower Bed Maintenance Services | LutzLandscaping.us
Lutz, FL Professional Flower Planting Services | LutzLandscaping.us
Lutz, FL Professional Hedging Services | LutzLandscaping.us
Lutz, FL Professional Mulching Services | LutzLandscaping.us
Lutz, FL Professional Plant Removal Services | LutzLandscaping.us
Lutz, FL Professional Pruning Services | LutzLandscaping.us
Lutz, FL Professional Weeding Services | LutzLandscaping.us
Lutz, FL Professional Lawn Care Services | LutzLandscaping.us
Lutz, FL Professional Artificial Grass Installation Services | LutzLandscaping.us
Lutz, FL Professional Dethatching Lawn Services | LutzLandscaping.us
Lutz, FL Professional Fertilizing Lawn Services | LutzLandscaping.us
Lutz, FL Professional Hydroseeding Services | LutzLandscaping.us
Lutz, FL Professional Lawn Aeration Services | LutzLandscaping.us
Lutz, FL Professional Lawn Edging Services | LutzLandscaping.us
Lutz, FL Professional Lawn Grubs Control Services | LutzLandscaping.us
Lutz, FL Professional Lawn Installation Services | LutzLandscaping.us
Lutz, FL Professional Lawn Leveling Services | LutzLandscaping.us
Lutz, FL Professional Lawn Mowing Services | LutzLandscaping.us
Lutz, FL Professional Lawn Renovation Services | LutzLandscaping.us
Lutz, FL Professional Lawn Seeding Services | LutzLandscaping.us
Lutz, FL Professional Sod Installation Services | LutzLandscaping.us