Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

July 22, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: Adobe Acrobat Chrome extension users
Incident: A UXSS vulnerability in the Adobe Acrobat extension enabled cross-origin data theft from WhatsApp Web.
Impact: Unauthorized access to private WhatsApp messages, chat lists, and contact data.
Attacker: Unidentified threat actors
Analysis: Researchers discovered a UXSS vulnerability (CVE-2026-48294) that breaks the browser’s same-origin policy. By tricking a user into visiting a crafted page, attackers can leverage the extension’s internals to inject forms into WhatsApp Web’s DOM. This enables the extraction of chat histories and contact lists without requiring malware installation or credential phishing.
Recommendations: Update the Adobe Acrobat Chrome extension to the latest version immediately.; Exercise caution when clicking links from untrusted sources or unexpected marketing emails.; Audit installed browser extensions and remove those that are no longer necessary.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *