Adobe Acrobat Extension Flaw Could Let Malicious Sites Read WhatsApp Web Chats — What to Know

Adobe Acrobat Extension Flaw Could Let Malicious Sites Read WhatsApp Web Chats — What to Know

A flaw in Adobe’s Acrobat Chrome extension could let malicious websites read private WhatsApp Web chats. Here’s what happened, who faced risk, and how to protect your browser and messages.

What Happened?

According to BleepingComputer, a flaw in Adobe Acrobat’s Chrome extension could let malicious websites read private conversations displayed in WhatsApp Web.

Guardio researchers named the attack HermeticReader and tracked the flaws as CVE-2026-48294. The issue affected extension versions 26.5.2.1 and earlier.

Adobe fixed the problem in version 26.5.2.3. Guardio said it found no evidence that criminals had used the flaw against real users.

Private chats can contain names, phone numbers, financial details, travel plans, or other information that criminals may misuse. Similar personal details may also be leaked through data breaches that receive little public attention.

Many people do not know their information was leaked until they receive suspicious messages or notice unusual account activity. Automatic monitoring can help you identify these risks earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Faced Risk and What Information Could Be Accessed?

People using an affected Adobe Acrobat extension with WhatsApp Web open in Chrome faced potential risk.

A malicious website could direct the extension to read information currently displayed in WhatsApp Web. This could include:

  • Chat lists
  • Contact names
  • Messages
  • Your WhatsApp profile name
  • Conversation content

Messages that were not loaded or displayed could not be accessed.

The attack also did not need WhatsApp session cookies, which help keep you signed in.

Guardio found no confirmed victims, so there is no public list of people whose chats were taken.

Private conversations may contain names, phone numbers, travel plans, financial details, or other information criminals could misuse.

These details can make phishing messages and impersonation attempts seem more believable. 

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

How Malicious Websites Could Read WhatsApp Web

The attack began when someone visited a malicious website while using the affected Adobe Acrobat extension.

The website could secretly load an internal Adobe page inside an iframe, which is a hidden page placed within another webpage.

That internal page accepted commands without properly checking where they came from.

The commands could activate Hermes, the Adobe extension tool that connects with WhatsApp Web.

Hermes could then control parts of WhatsApp Web, read displayed text, and send that text to a server controlled by criminals.

Researchers also showed that criminals could replace WhatsApp’s device-linking QR code.

However, account takeover would still require you to scan the replaced code with your phone.