Adobe's Acrobat Chrome extension leaked WhatsApp Web chats to any website you visited
Researchers at Guardio Labs found a chain of flaws, tracked as CVE-2026-48294, that let any web page silently read messages, contacts and chat lists from WhatsApp Web. Adobe patched the extension within two days.

Key points
- Guardio Labs disclosed a flaw chain, tracked as CVE-2026-48294 and named HermeticReader, in the Adobe Acrobat extension for Google Chrome.
- The bug affected Adobe Acrobat Chrome extension versions 26.5.2.1 and earlier, installed on roughly 329 million browsers.
- A single visit to a booby-trapped web page was enough to read a victim's WhatsApp Web chat list, contact names, profile name and open conversations.
- Adobe shipped a fix in version 26.5.2.3, pushed automatically to users over a weekend, two days after the report.
- Guardio says it has seen no signs of the flaw being used in real attacks.
An extension that most people installed to open PDF files in their browser turned out to be a doorway into their private WhatsApp messages.
Researchers at the security firm Guardio Labs found that the Adobe Acrobat extension for Chrome could be tricked into handing over the contents of a user's WhatsApp Web tab to any website they happened to visit. No password prompt. No warning. One page load was enough.
The flaw chain, first reported by BleepingComputer, is tracked as CVE-2026-48294 and nicknamed HermeticReader. It affects Adobe Acrobat Chrome extension versions 26.5.2.1 and below. Adobe has fixed it in version 26.5.2.3.
How could a PDF extension read your WhatsApp messages?
The extension contained a hidden helper, called Hermes, whose job was to let Adobe Acrobat open PDF files shared inside WhatsApp Web.
To do that, Hermes needed the power to reach into a WhatsApp tab and read what was on the screen. That is a lot of trust to hand a browser add-on. The problem was that the extension did not check who was asking it to use that power.
Guardio found that any web page could load one of the extension's own internal pages inside an invisible frame and pass it instructions through a web address. The extension's background service then acted on those instructions as if Adobe itself had sent them.
From there, the attacking page could tell Hermes to point at the victim's open WhatsApp Web tab and copy whatever was rendered there. Guardio demonstrated the theft by quietly injecting a hidden form into WhatsApp Web, sweeping the visible page content into it, and posting it to a server the researchers controlled.
The leaked data included the chat list, contact names, the user's profile name, and the text of conversations that were open on screen. Messages that had not been loaded were not exposed.
The attack did not need to steal any login cookie. It piggybacked on the session the user already had open.
Should ordinary WhatsApp users be worried?
Probably not, but check your extension version today.
Adobe pushed the fixed extension, version 26.5.2.3, automatically to Chrome users. Most people will already have it. To be sure, open Chrome, go to the extensions page, find Adobe Acrobat, and confirm the version number.
Guardio's principal researcher, Nati Tal, told reporters the team found the bug only four hours after Adobe introduced it in an update, and that Adobe patched it within two days, over a weekend. Guardio says there is no sign anyone else found or used the flaw.
One more scenario is worth flagging. The same trick could, in theory, swap out the QR code that WhatsApp shows when you link a new device, letting an attacker link their own phone to your account. That attack only works if the victim actually scans the swapped code, which is a big ask.
The wider lesson is a familiar one. A browser extension is not a small thing. It often has permission to read every page you open, including your bank, your email and your messages. HermeticReader is a clean example of what happens when one of those extensions treats instructions from a random web page as if they came from the vendor itself.
Adobe told Guardio it does not usually publish security bulletins for consumer products, but has acknowledged the flaw.



