HermeticReader Flaw (CVE-2026-48294) in Adobe’s Acrobat Extension Exposed WhatsApp Chats to Any Website
- Adobe flaw: Guardio Labs uncovered HermeticReader, tracked as CVE-2026-48294, in Adobe's Acrobat Chrome extension.
- Massive reach: The flaw affected roughly 329 million browsers running the extension.
- Exposed WhatsApp chats: The one-click WhatsApp data exfiltration vulnerability impacted chat lists and texts, among others.
A chain of vulnerabilities in the Adobe Acrobat Chrome extension could turn a single click into a full WhatsApp data exfiltration. It affected an extension installed on roughly 329 million browsers and was assigned CVE-2026-48294, carrying a CVSS score of 7.4. Guardio Labs documented the flaw, which it named HermeticReader.
HermeticReader Turns One Click Into WhatsApp Takeover
The exploit abuses Hermes, Adobe's integration engine for WhatsApp Web, which stays dormant until a specific feature flag is activated in the extension's internal storage. A victim who already has the extension installed only needs to visit an attacker-controlled page.
From there, the chain reaches into WhatsApp Web and hands over:
- rendered chat lists,
- contact names,
- message text,
- profile details.
The attack does not require malware installation, phished passwords, session cookies, or a zero-day in WhatsApp itself, and the attacker can proceed without an Adobe account or foothold, the analysis said.
"The setup is almost insultingly ordinary," Guardio researcher Shaked Biner said – a page dressed up to look like something you'd land on from a search result or a marketing email.
Adobe Patch Available
Guardio's custom agentic AI research harness surfaced the issue within hours of Adobe shipping version 26.5.2.1 on June 3, 2026, paired with human-led verification. The system traced the reachable exploit chain against a 138-case service-worker message dispatcher.
The company acknowledged, fixed, and shipped a patched version, 26.5.2.3, across one weekend, with CVE-2026-48294 issued days later. The fix was delivered automatically through the Chrome Web Store, though security teams recommend verifying installed extension versions are current.
In other recent news, OpenAI's own AI models escaped their Sandbox to hack Hugging Face and cheat a benchmark.








