The Adobe Acrobat extension for Chrome might permit you to entry conversations and information rendered on WhatsApp Net with out authentication.
The assault, tracked collectively as CVE-2026-48294 by researchers at cybersecurity agency Guardio, exploits a set of vulnerabilities named HermeticReader.
To use them, merely direct a goal operating an Adobe Acrobat extension to an internet web page beneath the menace actor’s management.
steal WhatsApp communications
This subject happens as a result of an Adobe extension permits web sites to disguise attacker instructions as inner extension messages, activate WhatsApp integration, and redirect privileged DOM operations to WhatsApp tabs with predictable tab IDs.
By offering that ID to the extension, an attacker may ship instructions to the WhatsApp net tab to the Hermes engine, which acts as an middleman between Acrobat and WhatsApp.
Hermes is the mixing engine that the Adobe Acrobat Chrome extension makes use of to deal with interactions with WhatsApp Net. It stays dormant till sure characteristic flags are activated within the extension’s inner storage.
As soon as run, Hermes can obtain requests from the mixing, open PDF recordsdata shared by way of WhatsApp, and ship again responses. It permits you to ship instructions on to the tab operating the messaging service by way of scripts that may manipulate the WhatsApp Doc Object Mannequin (DOM).
In a report shared with BleepingComputer, Guardio mentioned HermeticReader exploits three vulnerabilities to permit “unauthenticated, single-access, zero-click writes to the extension’s personal storage from any net web page.”
“This extension has an inner HTML useful resource that’s a part of the extension, however any web page can embrace it as an iframe,” Guardio Labs defined.
“The best way this inner HTML web page receives instructions is thru URL parameters, that are later processed and despatched to the extension’s backend, a service employee, with all of the privileges utilized, with out checking whether or not the instructions got here from the precise Adobe content material script or from another web page,” the researchers informed BleepingComputer.
Guardio inserts a type in WhatsApp Net and replaces the precise physique of the web page with
.jpg)
Supply: Guardio Labs
For the reason that possibility with no worth outlined sends textual content content material and WhatsApp’s Content material Safety Coverage (CSP) had no restrictions on type actions, the browser reportedly despatched the rendered web page textual content to the attacker, permitting entry to the messaging information.
- chat listing
- contact title
- message
- profile title
- Dialog content material
Regardless of the massive reveal, HermeticReader assaults don’t require session cookies. Word that messages that aren’t loaded or rendered is not going to be leaked within the assault.
Guardio researchers point out one other state of affairs the place hackers take over WhatsApp accounts. By leveraging the identical DOM management performance, an attacker may exchange WhatsApp’s gadget hyperlink QR code and take management of a person’s account.
Nonetheless, this state of affairs requires appreciable effort because the sufferer should scan the changed QR code.
Fixes accessible
The HermeticReader flaw is tracked as CVE-2026-48294 and impacts Adobe Acrobat Chrome extension variations 26.5.2.1 and beneath.
This subject was mounted in 26.5.2.3 and robotically delivered to customers. Nonetheless, we suggest that you just test you probably have the most recent launch put in.
Guardio Labs Principal Researcher Nati Tal informed BleepingComputer that there is no such thing as a indication that CVE-2026-48294 has been actively exploited.
Researchers mentioned they found the flaw simply 4 hours after Adobe launched it by way of an extension replace. The seller responded shortly to the vulnerability report and launched a patch inside two days, over the weekend.
Guardio praised Adobe’s fast response and mentioned the seller’s fast actions have been according to the urgency of discovering such a flaw in an extension that’s “put in on roughly 329 million browsers.”
Adobe informed Nati Tal that it sometimes doesn’t launch safety info for shopper merchandise, however the firm acknowledged the flaw right here.
Customers ought to be sure that the Adobe Acrobat extension for Chrome is up to date to model 26.5.2.3.
Safety groups doc 54% of profitable assaults and subject a warning on solely 14%. The remaining strikes invisibly by way of the surroundings.
Picus’ whitepaper reveals the way to take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
