
CVE-2026-48294: Adobe Acrobat Extension — WhatsApp Web Chat Exposure (June 2026)
CVE-2026-48294 — Adobe Acrobat PDF Chrome Extension
CVE-2026-48294 is a high-severity vulnerability in the Adobe Acrobat PDF extension for Chrome, allowing attackers to bypass browser same-origin policy and access WhatsApp Web chat data. The flaw, dubbed HermeticReader, was not reported as actively exploited in the wild but exposed over 329 million users to silent chat surveillance until Adobe patched it in version 26.5.2.3.
Attack Vector
Attackers lure victims to a malicious website while the vulnerable Adobe Acrobat extension (Chrome extension ID: efaidnbmnnnibpcajpcglclefindmkaj) is active. The extension’s privileged context enables cross-origin requests, letting attackers read WhatsApp Web data—including chat lists, contact names, profile names, and message contents—without user interaction. The attack requires the victim to have both the extension installed and an active WhatsApp Web session in the same browser profile.
Who Is at Risk
All Chrome users with Adobe Acrobat PDF extension installed prior to version 26.5.2.3 are vulnerable. WhatsApp Web users are specifically at risk if they access the service in a browser with the affected extension. Both Adobe and WhatsApp are confirmed as impacted organizations. The vulnerability is global in scope, with hundreds of millions of installations affected.
Patch & Mitigate
- Patch: Upgrade Adobe Acrobat PDF Chrome extension to version 26.5.2.3 or later immediately.
- Workaround: Disable or remove the extension if patching is not possible.
- Detect: Review browser extension logs for unexpected cross-origin requests or access to WhatsApp Web domains originating from the extension (ID: efaidnbmnnnibpcajpcglclefindmkaj).
MITRE ATT&CK
- TA0001 — Initial Access: Attackers use malicious websites to gain a foothold via the vulnerable extension.
- TA0007 — Discovery: The extension’s flaw enables enumeration and extraction of chat and contact data from WhatsApp Web.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

