A Browser Extension Installed 300 Million Times Had a Flaw That Let Attackers Steal Your WhatsApp Messages

A security hole in Adobe's widely used browser extension meant that simply visiting the wrong website could hand criminals your private messages and contacts.

ThreatVectr Newsdesk· 3 min read
A close-up, editorial-style photograph of a rack of illuminated server hardware in a dark data centre, cooling fans visible, status LEDs casting blue and amber
Share

Key points

  • A vulnerability, meaning a security flaw in software, was found in an Adobe browser extension with more than 300 million installs worldwide.
  • The flaw allowed an attacker to steal WhatsApp messages and contact lists from a victim's device.
  • No complicated trick was required: the victim only needed to visit a malicious website the attacker controlled.
  • Adobe has since patched the extension, meaning a fix has been released.
  • Users who have not updated their browser extensions recently should do so now.

Three hundred million is a lot of people. To put it another way: if that extension were a country, it would be the fourth most populous on Earth. And for a window of time, every one of those installs carried a flaw that could empty out your WhatsApp inbox.

The vulnerability sat inside an Adobe browser extension, a small add-on program that users install into Chrome or similar browsers to extend what those browsers can do. Adobe's extensions are trusted by designers, photographers, and everyday users around the world. That trust is exactly what made this flaw dangerous.

The attack itself was grimly simple. A criminal sets up a website rigged to exploit the flaw. You visit that site, perhaps through a link in an email or a social media post. Nothing visible happens. Behind the scenes, the extension's security boundary breaks down, and your WhatsApp messages and contacts quietly travel to the attacker's server. No password needed. No file download required. Just a page load.

How did the flaw actually work?

The extension failed to properly check where certain requests were coming from, a classic mistake web developers have been warned about since the early 2000s. Security researchers call this type of weakness a cross-origin flaw, but the concept is old enough to have a dusty shelf in every web-security textbook. A malicious page could pretend to be a trusted source, and the extension believed it. The result: data walked out the door.

SecurityWeek first reported the details of the flaw. At the time of writing, a CVE identifier, which is the official tracking number assigned to a specific software vulnerability, had not been publicly assigned, so there is no NVD page to link to yet.

Adobe has patched the extension. The fix is out.

If you use any Adobe browser extension, open your browser's extension settings today and confirm you are running the latest version. Most browsers update extensions automatically, but that process is not always instant. Manually checking takes thirty seconds.

Also worth doing: look over any recent WhatsApp conversations for messages you did not send, or contacts you do not recognise. If something looks wrong, change your WhatsApp security code under Settings and let your contacts know.

The broader lesson here is not that Adobe is uniquely careless. Extensions from any vendor can carry flaws like this. The attack surface, meaning the total number of ways an attacker can reach you, grows every time you add an extension. Keep your list short, keep them updated, and remove anything you no longer use.

© 2026 Threat Vectr