In brief: A widely installed Adobe Chrome extension contained a security vulnerability that allowed attackers to access WhatsApp chats with minimal effort.
Security researchers have documented a critical vulnerability in the Adobe Acrobat Chrome extension that could be exploited to intercept WhatsApp messages. The extension was installed by over 300 million users.
The Adobe Acrobat extension for Google Chrome was among the most-installed browser plugins ever. However, security researchers identified a vulnerability that allowed attackers to extract confidential user data — specifically WhatsApp messages and associated metadata.
Attackers needed only a simple click or to manipulate users into interacting with malicious content. The extent of potential exposure is significant, as the extension was active on millions of browsers and would have had access to sensitive communication content.
For CISOs and security professionals, this incident is relevant as it demonstrates that even browser extensions from established vendors like Adobe — trusted by millions — can pose serious security risks. A key takeaway is the necessity to regularly review the permissions and behaviour of installed extensions and to provide users with clear guidelines for browser plugins.
Source: www.golem.de · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.