Adobe extension bug exposed WhatsApp chats in 329M installs
A flaw in the Adobe Acrobat Chrome extension installed in about 329 million browsers let attackers steal WhatsApp chats and contacts by tricking users into visiting a web page. Adobe patched it in June.
Security firm Guardio reported a vulnerability in the Adobe Acrobat Chrome extension that could be used to steal WhatsApp chats, contact lists and account details. The extension is installed in roughly 329 million Chrome browsers. Adobe released a patch in June after Guardio disclosed the issue.
Guardio named the exploit HermeticReader. The attack did not rely on a vulnerability in WhatsApp, malware, stolen credentials, or direct access to a victim’s device. Instead, researchers found a cross-origin data disclosure in the extension’s internal messaging.
Adobe classified the bug as a UXSS-type cross-origin data disclosure and assigned it CVE-2026-48294. The company updated the extension to close the messaging and storage weaknesses that enabled the chain of actions.
The exploit used a hidden frame on a web page to send unverified commands to the Acrobat extension. The extension did not validate those commands properly, which allowed the attacker to write data into the extension’s local storage. Writing that data could enable Hermes, a dormant integration engine built into the extension.
Once Hermes was activated, the engine could connect to WhatsApp Web in the background and scrape private information. Guardio demonstrated that an attacker could retrieve chats, contacts and account details in plain text without alerting the user. The exploit therefore bridged the extension and a user’s WhatsApp Web session without attacking WhatsApp itself.
Guardio published a demonstration video showing the sequence of actions and the data extraction. Adobe’s June update addressed the problem by adding checks to the extension’s messaging system and preventing web content from issuing unverified commands and writing to extension storage.
Guardio’s report noted that the attack required only that a user load a specially crafted web page; no further interaction was needed. Adobe released the patched extension to remove the exploit path and closed the vulnerability identified as CVE-2026-48294.








