Skip to content

Adobe Extension: Security Flaw Enabled Access to WhatsApp Chats

In a nutshell: An insufficiently protected internal HTML resource in the Adobe Acrobat extension allowed external websites to read WhatsApp chats, contact lists, and profile information.

Security researchers from Guardio Labs discovered a chain of vulnerabilities (CVE-2026-48294) in the Adobe Acrobat Chrome extension that allowed unauthenticated access to WhatsApp Web content. Adobe patched the flaw within two days.

The Chrome extension Adobe Acrobat in versions 26.5.2.1 and earlier contained a critical security vulnerability. Through an insufficiently protected URL parameter of an internal HTML resource, crafted websites could send commands to the extension’s service worker without requiring authentication. The internal HTML page was accessible to any website and could be embedded as an iframe. Commands were forwarded to the Hermes integration engine, which serves as the interface between the Adobe extension and WhatsApp Web.

Through this vulnerability, attackers could manipulate the Document Object Model of WhatsApp Web. In a laboratory demonstration, researchers from Guardio Labs showed how visible chat histories, contact lists, message content, and profile names could be transmitted to external servers via a form. Only content rendered in the browser was captured; unloaded or non-visible messages were not affected. The attack required neither session cookies nor any additional authentication mechanisms.

Adobe distributed the corrected version 26.5.2.3 automatically to users after the flaw was identified four hours after discovery and patched within two days. According to Guardio Labs, there were no indications of active exploitation outside laboratory conditions among the security research community.


Source: www.it-daily.net · Published July 23, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: