A now-patched vulnerability chain, dubbed HermeticReader, has been disclosed in the Adobe Acrobat Chrome extension — an extension with over 314 million users — tracked as CVE-2026-48294 with a CVSS score of 7.4. The flaw allowed any attacker-controlled webpage to silently access a visiting user's WhatsApp Web chats, contacts, and profile data without any additional user interaction beyond browsing the malicious page.
The vulnerability was discovered and responsibly disclosed by Guardio Labs researcher Shaked Biner, who described the issue as a vulnerability chain rather than a single discrete flaw. Adobe has since issued a patch, and the CVE is now remediated in updated versions of the extension. The scale of the potential attack surface — given the extension's enormous install base — made this a significant credential and privacy risk.
The attack required no elevated privileges and no active user interaction beyond visiting a crafted page, making it particularly dangerous for passive exploitation at scale. Users who had both the Adobe Acrobat Chrome extension and an active WhatsApp Web session open in their browser were silently exposed to data harvesting from any malicious or compromised website.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.