Adobe patched CVE-2026-48294 in Acrobat Chrome extension that could expose WhatsApp Web chats

Adobe fixed a flaw in its Acrobat extension for Chrome that could let a malicious website read private WhatsApp Web conversations from a victim's browser. Guardio tracked the issue as CVE-2026-48294, affecting Adobe Acrobat Chrome extension versions 26.5.2.1 and below; the attack used forged extension messages and WhatsApp integration features to redirect privileged page-control actions into an open WhatsApp Web tab, with no authentication needed beyond luring a user to an attacker-controlled page.
Why it matters: People using both WhatsApp Web and the Adobe Acrobat Chrome extension could have had chat contents exposed just by visiting a malicious page. Users should make sure the extension is updated to 26.5.2.3 or later, and organizations may want to review whether the extension is necessary in managed browsers.

Sources

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
info@thehackernews.com (The Hacker News) 2026.07.22 99% relevant
This article appears to cover the same underlying event: Adobe's fix for CVE-2026-48294 in the Acrobat Chrome extension, which allowed a malicious website to read WhatsApp Web data from a victim's browser session.
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
Eduard Kovacs 2026.07.22 99% relevant
This source is a direct report on the same event and adds attack details from Guardio, including the HermeticReader technique, abuse of the extension's internal messaging and local storage, activation of Adobe's Hermes integration, and the estimated install base of roughly 329 million browsers.
Adobe Chrome extension flaw let sites access private WhatsApp chats
Bill Toulas 2026.07.22 100% relevant
This article appears to be the initial report establishing the vulnerability, its impact on WhatsApp Web data exposure, the CVE identifier, and the fixed extension versions.
← Back to all stories