negativeSYS.SOURCE: The Hacker News• 2026-07-22T20:31:21+05:30
Adobe Acrobat Extension Vulnerability Enables Cross-Origin Data Access to WhatsApp Web
A newly disclosed vulnerability in the Adobe Acrobat Chrome extension allows malicious websites to access WhatsApp Web data through cross-origin scripting. The flaw, tracked as CVE-2026-48294, enables attackers to steal session-bound data without requiring malware or phishing.
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data.
The shortcoming has been codenamed HermeticReader by Guardio Labs. It's officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability
*** END OF TRANSMISSION ***