The Adobe Acrobat extension for Chrome presents a serious vulnerability that may enable unauthorized access to private conversations and data rendered on WhatsApp Web.
CVE-2026-48294, a critical vulnerability uncovered by researchers at cybersecurity firm Guardio, exploits a series of weaknesses termed HermeticReader.
Attackers can exploit this vulnerability by simply directing a target—who has the Adobe Acrobat extension installed—to a malicious web page.
Stealing WhatsApp Communications
This vulnerability arises because the Adobe extension allows websites to disguise malicious commands as internal messages from the extension. This enables the activation of WhatsApp integration, redirecting privileged DOM operations to WhatsApp tabs using predictable tab IDs.
By providing the tab ID to the extension, an attacker can send commands to the WhatsApp web tab via the Hermes engine, which acts as an intermediary between Acrobat and WhatsApp.
Hermes is the integration engine used by the Adobe Acrobat Chrome extension to manage interactions with WhatsApp Web. It remains inactive until certain feature flags within the extension’s internal storage are triggered.
Once activated, Hermes can receive requests from the integration, open PDF files shared via WhatsApp, and send back responses. This allows commands to be executed directly on the tab running WhatsApp, manipulating its Document Object Model (DOM).
In a report shared with BleepingComputer, Guardio reported that HermeticReader exploits three vulnerabilities to enable “unauthenticated, single-access, zero-click writes to an extension’s own storage from any web page.”
“This extension contains an internal HTML resource that can be included as an iframe by any web page,” Guardio Labs elaborated.
“The internal HTML page receives commands via URL parameters, which are then processed and transmitted to the extension’s backend service worker, retaining all privileges without verifying whether the commands originated from the Adobe content script or elsewhere,” the researchers told BleepingComputer.
Guardio has demonstrated that an attacker can inject a form into WhatsApp Web, replacing the actual page body with
.jpg)
Source: Guardio Labs
Since the option without a defined value transmits text content and WhatsApp’s Content Security Policy (CSP) imposes no restrictions on form actions, attackers can exploit this vulnerability to access sensitive messaging data.
- Chat Lists
- Contact Names
- Messages
- Profile Names
- Conversation Content
Despite this alarming discovery, HermeticReader attacks do not require session cookies; however, messages that are not loaded or rendered during the attack will not be exposed.
Researchers from Guardio noted another alarming scenario: hackers could potentially take over WhatsApp accounts by utilizing the same DOM control features. An attacker could replace the QR code for the device link, enabling account takeover. This, however, necessitates the victim scanning the fraudulent QR code.
Available Fixes
The HermeticReader flaw, documented as CVE-2026-48294, affects Adobe Acrobat Chrome extension versions 26.5.2.1 and earlier.
Adobe promptly addressed this issue in version 26.5.2.3, which has been automatically distributed to users. It is advisable to verify that the latest version is installed.
Guardio Labs Principal Researcher Nati Tal informed BleepingComputer that there is no evidence suggesting that CVE-2026-48294 has been actively exploited.
Researchers detected the vulnerability just four hours after Adobe issued an extension update. Adobe swiftly responded to the vulnerability report, issuing a patch within just two days, even over the weekend.
Guardio commended Adobe’s rapid response, underscoring the urgency given that the extension is installed on approximately 329 million browsers.
Adobe confirmed to Nati Tal that while it typically refrains from sharing security details for consumer products, they did acknowledge this particular flaw. Learn more here.
Users are strongly encouraged to ensure their Adobe Acrobat extension for Chrome is updated to version 26.5.2.3 to safeguard against potential exploits.
Security teams have reported that only 54% of successful attacks are documented, while merely 14% are issued as warnings. The remainder goes unnoticed within the environment.
Picus’ whitepaper illustrates how to evaluate your SIEM and EDR rules in breach and attack simulations to ensure that threats remain undetected.
Source: www.bleepingcomputer.com




