← All briefs
Brief·2 sources22 Jul 2026

CVE-2026-48294 Exploited To Silently Steal WhatsApp Data Via Adobe Acrobat Extension

vulnerability-disclosurecredential-theftdata-exfiltrationpatch-managementinitial-access

Summary

A now-patched vulnerability chain, dubbed HermeticReader, has been disclosed in the Adobe Acrobat Chrome extension — an extension with over 314 million users — tracked as CVE-2026-48294 with a CVSS score of 7.4. The flaw allowed any attacker-controlled webpage to silently access a visiting user's WhatsApp Web chats, contacts, and profile data without any additional user interaction beyond browsing the malicious page.

The vulnerability was discovered and responsibly disclosed by Guardio Labs researcher Shaked Biner, who described the issue as a vulnerability chain rather than a single discrete flaw. Adobe has since issued a patch, and the CVE is now remediated in updated versions of the extension. The scale of the potential attack surface — given the extension's enormous install base — made this a significant credential and privacy risk.

The attack required no elevated privileges and no active user interaction beyond visiting a crafted page, making it particularly dangerous for passive exploitation at scale. Users who had both the Adobe Acrobat Chrome extension and an active WhatsApp Web session open in their browser were silently exposed to data harvesting from any malicious or compromised website.

Timeline

  1. 22 July 2026
    Guardio Labs discloses HermeticReader vulnerability chain as CVE-2026-48294
    Researcher Shaked Biner of Guardio Labs publicly disclosed CVE-2026-48294, a vulnerability chain in the Adobe Acrobat Chrome extension enabling silent WhatsApp Web data theft from any attacker-controlled webpage.
  2. 22 July 2026
    Adobe releases patch for CVE-2026-48294 in Acrobat Chrome extension
    Adobe issued a remediated update to the Adobe Acrobat Chrome extension, addressing the HermeticReader flaw in coordination with the public disclosure by Guardio Labs.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs, and response recommendations — available inside the Deltabridge platform.

CVE-2026-48294 Exploited To Silently Steal WhatsApp Data Via Adobe Acrobat Extension — Deltabridge