Adobe Acrobat extension Chrome HermeticReader security flaw (CVE-2026-48294)
Vulnerability
Summary
Hide ▲
Show ▼
The Adobe Acrobat extension for Chrome flaw CVE-2026-48294 let attacker-controlled pages reach WhatsApp Web conversations and rendered data without authentication. The issue affected versions 26.5.2.1 and below and could expose loaded chat content from the browser tab. Adobe fixed the flaw in 26.5.2.3, and users were told to update to the latest release.
Related Happenings
Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw
Vulnerability
H score30
First: 19.03.2026 22:01
Last: 19.03.2026 22:01
Sources 1
About this happening:
PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...
Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw
VulnerabilityAbout this happening: PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...
Timeline
-
22.07.2026 16:22 2 articles · 1h ago
Guardio reports HermeticReader in the Adobe Acrobat extension for Chrome
Initial DisclosureGuardio reported CVE-2026-48294, dubbed HermeticReader, in the Adobe Acrobat extension for Chrome, describing a single-visit, zero-click chain that could let an attacker-controlled page access conversations and rendered data in WhatsApp Web without authentication. The flaw affected versions 26.5.2.1 and below, no active exploitation was observed, and Adobe fixed the issue in 26.5.2.3.
Show sources
- Adobe Chrome extension flaw let sites access private WhatsApp chats — www.bleepingcomputer.com — 22.07.2026 16:22
- Adobe Chrome extension flaw let sites access private WhatsApp chats — www.bleepingcomputer.com — 22.07.2026 16:22