Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.

Browser vulnerability

A highly popular Chrome extension made by Adobe was affected by a vulnerability that could have been exploited to silently steal a user’s WhatsApp chats and contacts.

According to web and browser security firm Guardio, whose researchers discovered and reported the vulnerability to Adobe, an attacker could have stolen users’ WhatsApp data simply by tricking them into visiting a seemingly harmless webpage.

The exploit did not involve a WhatsApp vulnerability, malware deployment, compromised credentials, or access to the targeted device. 

The attack, dubbed HermeticReader, affected the Adobe Acrobat Chrome extension, which is installed in approximately 329 million browsers.

Adobe patched the vulnerability in June, shortly after being informed of its existence. The software giant assigned it CVE-2026-48294 and described it as a UXSS-class cross-origin data disclosure vulnerability.

Under the hood, the attack abuses a lack of security checks within the Adobe extension’s internal messaging system. When a victim loads the malicious site, a hidden frame tricks the extension into accepting unverified commands. 

Advertisement. Scroll to continue reading.

This allows the attacker to silently write to the extension’s local storage and enable Hermes, a dormant integration engine built by Adobe. Once activated, this engine bridges the gap to WhatsApp Web, enabling the attacker to invisibly scrape the victim’s private chats, contacts, and account details in plain text. 

Guardio has published a video showing a HermeticReader attack in action:

Related: Vibe-Coded Apps Riddled With Exploitable Security Flaws

Related: Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

Related: OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

Assaf Keren, who previously served as CSO/CISO at Qualtrics and PayPal, is Meta's new CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.