A security vulnerability in the Adobe Acrobat extension for Google Chrome could have allowed attackers to access conversations and other data displayed in WhatsApp Web without requiring authentication.

The vulnerability, discovered by researchers at Guardio Labs, has been tracked as CVE-2026-48294 and is collectively known as HermeticReader.

The attack required only that a victim using the vulnerable Adobe Acrobat Chrome extension visit a malicious website controlled by an attacker. Researchers found that the extension could be tricked into treating attacker-generated commands as legitimate internal messages, allowing them to activate its hidden WhatsApp integration and interact with an open WhatsApp Web tab.

At the center of the issue is Hermes, the integration engine that enables the Adobe Acrobat extension to communicate with WhatsApp Web. Once activated, Hermes can send commands directly to the WhatsApp tab and manipulate its Document Object Model (DOM), giving attackers a way to interact with content displayed inside the browser.

Guardio researchers identified a chain of vulnerabilities that allowed a malicious webpage to write data into the extension’s internal storage without authentication. They demonstrated that an attacker could inject a form into WhatsApp Web, manipulate the page, and exfiltrate rendered information to an attacker-controlled server.

According to the researchers, the attack could expose information currently loaded in WhatsApp Web, including chat lists, contact names, message contents, profile names, and active conversations. The exploit does not require access to session cookies, although messages that were not loaded or displayed in the browser could not be stolen.

READ
Germany, U.S. Shut Down Kratos Phishing Platform, Arrest Developer in Indonesia

The researchers also described a separate attack scenario in which the same DOM-control capability could be used to replace WhatsApp’s device-linking QR code with one controlled by an attacker. If the victim scanned the substituted QR code, the attacker could potentially link the victim’s WhatsApp account to their own device. However, this attack requires user interaction and is considered more difficult to execute.

The vulnerabilities affect Adobe Acrobat Chrome Extension version 26.5.2.1 and earlier. Adobe has fixed the issue in version 26.5.2.3, which has been automatically rolled out to users. Guardio said it found no evidence that the flaw had been actively exploited and praised Adobe for releasing a patch within two days of receiving the report.


Buy ExpressVPN with PayPal or Credit Card

Users are advised to verify that their Adobe Acrobat Chrome extension is updated to version 26.5.2.3 or later to ensure they are protected from the vulnerability.

Advertisement