HermeticReader Flaw (CVE-2026-48294) in Adobe’s Acrobat Extension Exposed WhatsApp Chats to Any Website

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Adobe flaw: Guardio Labs uncovered HermeticReader, tracked as CVE-2026-48294, in Adobe's Acrobat Chrome extension.
  • Massive reach: The flaw affected roughly 329 million browsers running the extension.
  • Exposed WhatsApp chats: The one-click WhatsApp data exfiltration vulnerability impacted chat lists and texts, among others.

A chain of vulnerabilities in the Adobe Acrobat Chrome extension could turn a single click into a full WhatsApp data exfiltration. It affected an extension installed on roughly 329 million browsers and was assigned CVE-2026-48294, carrying a CVSS score of 7.4. Guardio Labs documented the flaw, which it named HermeticReader.

HermeticReader Turns One Click Into WhatsApp Takeover

The exploit abuses Hermes, Adobe's integration engine for WhatsApp Web, which stays dormant until a specific feature flag is activated in the extension's internal storage. A victim who already has the extension installed only needs to visit an attacker-controlled page. 

From there, the chain reaches into WhatsApp Web and hands over:

HermeticReader attack chain | Source: Guardio Labs
HermeticReader attack chain | Source: Guardio Labs

The attack does not require malware installation, phished passwords, session cookies, or a zero-day in WhatsApp itself, and the attacker can proceed without an Adobe account or foothold, the analysis said

The iframe trick hiding attacker commands | Source: Guardio Labs
The iframe trick hiding attacker commands | Source: Guardio Labs

"The setup is almost insultingly ordinary," Guardio researcher Shaked Biner said – a page dressed up to look like something you'd land on from a search result or a marketing email.

Adobe Patch Available

Guardio's custom agentic AI research harness surfaced the issue within hours of Adobe shipping version 26.5.2.1 on June 3, 2026, paired with human-led verification. The system traced the reachable exploit chain against a 138-case service-worker message dispatcher. 

The company acknowledged, fixed, and shipped a patched version, 26.5.2.3, across one weekend, with CVE-2026-48294 issued days later. The fix was delivered automatically through the Chrome Web Store, though security teams recommend verifying installed extension versions are current.

In other recent news, OpenAI's own AI models escaped their Sandbox to hack Hugging Face and cheat a benchmark.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: