Find notable cyber news and cases, enriched with sources, timelines, and signals.

Adobe Acrobat extension Chrome HermeticReader security flaw (CVE-2026-48294)

Vulnerability
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

The Adobe Acrobat extension for Chrome flaw CVE-2026-48294 let attacker-controlled pages reach WhatsApp Web conversations and rendered data without authentication. The issue affected versions 26.5.2.1 and below and could expose loaded chat content from the browser tab. Adobe fixed the flaw in 26.5.2.3, and users were told to update to the latest release.

Related Happenings

Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw

Vulnerability
H score30 First: 19.03.2026 22:01 Last: 19.03.2026 22:01 Sources 1

About this happening: PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...

Timeline

  1. 22.07.2026 16:22 2 articles · 1h ago

    Guardio reports HermeticReader in the Adobe Acrobat extension for Chrome

    Initial Disclosure

    Guardio reported CVE-2026-48294, dubbed HermeticReader, in the Adobe Acrobat extension for Chrome, describing a single-visit, zero-click chain that could let an attacker-controlled page access conversations and rendered data in WhatsApp Web without authentication. The flaw affected versions 26.5.2.1 and below, no active exploitation was observed, and Adobe fixed the issue in 26.5.2.3.

    Show sources