Adobe Patches Acrobat Chrome Extension Flaw That Exposed WhatsApp Web Chats to Any Website | Free Download

According to a report by cybersecurity firm Guardio shared with BleepingComputer, Adobe has patched a series of vulnerabilities in its Acrobat Chrome extension that previously allowed any website to access conversations in WhatsApp Web without proper authentication.

The vulnerabilities, collectively identified as CVE-2026-48294 and referred to as HermeticReader, affect Adobe Acrobat Chrome extension versions 26.5.2.1 and earlier.

Adobe has addressed the issue in version 26.5.2.3, which rolls out automatically, but Guardio advises users to verify that they are running the updated release.

Exploiting the flaw requires only that a user with the extension installed visit a malicious webpage. Guardio reports there is no indication that the vulnerability has been actively exploited.

How the attack worked and what data was exposed

The Adobe Acrobat extension uses an integration engine called Hermes to manage interactions with WhatsApp Web. Hermes remains inactive unless the feature flag is enabled in the extension’s internal storage.

Once activated, it can open a PDF shared through WhatsApp and send commands to the tab running the messaging service, manipulating WhatsApp’s document object model.

According to Guardio, HermeticReader exploits three vulnerabilities that together enable an unauthenticated, single-visit, zero-click write from any web page to the extension’s own storage.

The extension includes an internal HTML resource that any page can embed as an iframe. This resource receives the command via a URL parameter, which is then sent to the extension’s service worker without verifying whether the command originated from a valid Adobe Content Script.

By providing a predictable tab ID, an attacker can disguise commands as internal extension messages, activate WhatsApp integration, and redirect the extension’s privileged DOM operations to a WhatsApp web tab.

Guardio performed the data theft by injecting a form into WhatsApp Web, moving the live body of the page into an options element, and submitting the form to an attacker-controlled server.

Since an option element without a specific value submits its own text content, and WhatsApp’s content security policy reportedly lacks form-action restrictions, the browser sent the page’s text to the attacker.

The exposed data includes chat lists, contact names, messages, profile names and conversation contents. Session cookies were not required for the attack. Guardio says that the messages that did not load or appear on the page were not leaked.

Guardio also described a second scenario where an attacker could use the same DOM control functions to alter the WhatsApp device-linking QR code and take over the account. This method requires the victim to scan the substituted QR code, which adds significant complexity and makes it less practical than other data theft techniques.

Disclosure timeline and steps to take now

Guardio’s lead researcher, Nati Tal, informed BleepingComputer that the company discovered the vulnerability just four hours after Adobe included it in an extension update. Adobe released a patch within two days, over a weekend. Guardio praised the quick response, noting that the extension is installed on approximately 329 million browsers.

Adobe told Guardio that it does not typically issue security bulletins for consumer products but made an exception in this case. Users of the Adobe Acrobat Chrome extension should verify that they have the latest patch version, as the fix requires updating to version 26.5.2.3.

To do this, open Chrome and go to chrome://extensions in the address bar. Turn on developer mode using the toggle in the top right corner to see the extension version number.

Find Adobe Acrobat and check if the version is 26.5.2.3 or later. If it’s 26.5.2.1 or lower, open the Chrome menu, select Extensions, then Manage Extensions, and click Update to force an update. Restart Chrome after updating and re-verify the version.

Users who do not use the WhatsApp integration or extension can remove it from the Manage Extensions page as an extra precaution.

The patch is distributed to users automatically in version 26.5.2.3. Guardio has not seen any exploitation of the vulnerability before the patch was released, but due to the extension’s large user base, unpatched instances still pose a risk until the update spreads. Adobe has not issued any consumer security bulletins about this issue other than confirming it with Guardio.

Thanks for being a Ghax reader. The post Adobe patches Acrobat Chrome extension flaw that exposes WhatsApp web chat on any website appeared first on gHacks.

Source:Ghacks

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top