Bottom line: The Adobe Acrobat Chrome extension allowed unauthenticated access to WhatsApp Web chats due to missing access controls.
A security vulnerability in the Adobe Acrobat extension for Chrome enabled access to WhatsApp Web conversations without requiring authentication. This could have given attackers access to private messages and user data.
The Chrome extension from Adobe Acrobat was vulnerable to a flaw that enabled access to conversations and data displayed in WhatsApp Web without requiring authentication. This technical gap allowed potential attackers or malicious websites to exfiltrate private messages and associated metadata.
For CISOs, this case represents a typical browser extension vulnerability scenario: widely distributed browser add-ons with extensive functionality (such as PDF editing) receive broad permissions by default that go beyond their primary function. Without strict isolation and origin policies, these permissions can be exploited by any visited website to access other tabs or web applications.
In response, organizations should check the version number of the Adobe Acrobat extension and enforce an update to the patched version. At the enterprise level, an inventory of critical browser extensions in use and a policy to restrict extension permissions is recommended. Browser isolation or blocking WhatsApp Web in untrusted contexts can serve as mitigation until all systems are patched.
Source: www.bleepingcomputer.com · Published July 22, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.