Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

The Hacker News by The Hacker News
July 22, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananJul 22, 2026Vulnerability / Browser Security

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data.

The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability described as a case of universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability. It affects all versions of the extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) prior to and including 26.5.2.2.

Successful exploitation of the flaw can bypass the browser’s same-origin policy and access data linked to the victim’s session across origins. The only prerequisite is that it requires user interaction. A victim must be convinced into visiting a maliciously crafted URL or interact with a compromised web page that triggers the extension’s vulnerable code path.

In other words, an attacker can weaponize the flaw to obtain cross-origin read access to session-bound data. This can include authenticated content from third-party web applications loaded in the victim’s browser.

“The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.,” Guardio Labs researcher Shaked Biner said in a report shared with The Hacker News. “The visitor, who already has the Adobe Acrobat extension installed, opens that page.”

“The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view – the chat list, contact names, messages, the profile name, the text of whatever conversation is open – the whole WhatsApp in the attacker’s hands.”

What’s notable about the flaw is that it does not require a bad actor to install malware through some other means, phish a user’s credentials, or extract their session cookie. All it needs is for the victim to visit the crafted web page.

The entire sequence of actions is as follows –

  • An attacker-controlled page calls an iframe element loaded from the extension resources.
  • The iframe sends commands to alter settings to activate the Hermes engine, which handles WhatsApp integration in the extension only if a specific feature flag is enabled (“floodgate-add”).
  • The attacker page opens WhatsApp Web in a browser tab in the background.
  • The iframe sends commands directly to the engine directed against the WhatsApp tab after obtaining the tab’s numeric ID.
  • The engine manipulates WhatsApp Web’s by injecting a POST form into WhatsApp’s DOM to steal WhatsApp data.

“Why does submitting a form carry chat text out of WhatsApp’s origin? Two enablers deep from the HTML specifications: An option element with no value attribute submits its text content – and the text content of a node is the concatenation of everything rendered beneath it,” Biner explained. “Move the live body in, and the option’s submitted value becomes the entire rendered page text!”

“The second enabler is that WhatsApp Web’s content security policy that ships no form-action directive, and per the spec that absence means a top-level form submission may navigate to any origin. So WhatsApp itself performs the navigation, POSTing its own rendered DOM to our controlled endpoint and then dutifully rendering whatever we send back.”

As a result, a threat actor can exploit HermeticReader to capture the rendered chat list, contact names, message previews, the profile name, and the visible text of the open conversation.

“The industry pours its attention into the dramatic exploit classes and leaves the plumbing to the assumption that nobody will ever look hard at it,” Guardio concluded. “Composition is the threat. Plumbing-level flaws compose into building-level collapse, and the bigger the install base, the longer the building stands before anyone checks the joints.”



Source link

The Hacker News

The Hacker News

Next Post
Cambium Networks Introduces High Density Wi-Fi 7 Solution for the Enterprise

Cambium Networks Introduces High Density Wi-Fi 7 Solution for the Enterprise

Recommended.

Hitachi Vantara Named a Leader in 2026 GigaOm Radar for Object Storage for Strength in Storage Optimization and Enterprise Scalability

Hitachi Vantara Named a Leader in 2026 GigaOm Radar for Object Storage for Strength in Storage Optimization and Enterprise Scalability

April 9, 2026
Aduna Accelerates Network API Commercialization in Brazil with Vivo, Claro, and TIM Brasil

Aduna Accelerates Network API Commercialization in Brazil with Vivo, Claro, and TIM Brasil

October 23, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
Anaconda Extends AI-Native Application Development With Acquisition

Anaconda Extends AI-Native Application Development With Acquisition

May 1, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
This Scammer Used an AI-Generated MAGA Girl to Grift ‘Super Dumb’ Men

This Scammer Used an AI-Generated MAGA Girl to Grift ‘Super Dumb’ Men

April 21, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio