🟠 High | Source: The Hacker News
A now-patched vulnerability in the Adobe Acrobat Chrome extension, used by over 314 million people, allowed malicious websites to silently read a user’s WhatsApp Web data. Dubbed HermeticReader and tracked as CVE-2026-48294, the flaw could expose private messages and files without any interaction from the victim. The sheer scale of the extension’s install base makes this a significant supply-chain and browser security concern.
Security Architect’s Take: Audit your organisation’s managed Chrome browser policies to identify unapproved or unvetted extensions with broad host permissions — Adobe Acrobat is a common default install that may not be actively reviewed. Ensure extension allowlisting policies are enforced via Chrome Enterprise and that users are on the latest patched version of the Adobe Acrobat extension.
Original advisory: Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data