preloader

· digital-security digital-privacy browser-security whatsapp adobe europe vulnerability-management

HermeticReader: A Flaw in a 329 Million Install Chrome Extension Let Any Website Read Your WhatsApp Web Chats

Source: The Hacker News / Guardio Labs / BleepingComputer

Guardio Labs disclosed a vulnerability on 22 July that shows how little it takes to turn a completely unrelated piece of software into a privacy disaster. Named HermeticReader and tracked as CVE-2026-48294, the flaw sat in the Adobe Acrobat PDF extension for Chrome, an add-on installed in roughly 329 million browsers worldwide, and let any website inject commands into it. In practice, that meant a malicious or compromised page could silently reach into an open WhatsApp Web tab and exfiltrate chats, contacts and profile data, with no click, no download and no credential theft needed from the victim.

A universal cross-site scripting flaw in a tool nobody thinks twice about

CVE-2026-48294 is a universal cross-site scripting, or UXSS, class cross-origin data disclosure bug affecting every version of the extension up to and including 26.5.2.2. Because the extension held broad page access as part of its normal PDF-handling function, a page visited in any tab could use it as a bridge into other open tabs, including a live WhatsApp Web session. In one proof of concept, Guardio researchers injected a form directly into the WhatsApp Web interface and exfiltrated the rendered content to an external server, all without the extension or WhatsApp itself doing anything unusual.

The fix shipped fast, the exposure window did not

Adobe was informed, patched, and shipped version 26.5.2.3 within days, which Guardio publicly credited as a fast and clean response. The extension updates automatically for most users, and Guardio reported no evidence of exploitation in the wild before the patch landed. That is the good outcome here. The uncomfortable part is how long a bug like this can sit undetected in software that almost nobody audits, because it is not the browser, not the messaging app and not obviously security-relevant, just a PDF reader plugin that happens to have been granted sweeping page permissions.

Why this matters beyond one extension

European businesses increasingly run substantial parts of customer support, sales and internal coordination through WhatsApp Web inside ordinary business browsers, often alongside a long tail of browser extensions nobody has reviewed in months or years. HermeticReader is a clean illustration of how a single over-permissioned extension can become the weakest link in an otherwise well-secured environment, exposing conversations that were never meant to leave the app they were sent in. Confirming that Acrobat extensions are on 26.5.2.3 or later is a five-minute check, but the bigger question it raises, what else is sitting in your employees’ browsers with permissions nobody has looked at, is not.

If you want a proper audit of the browser extensions running across your organisation, or help building a policy for what gets installed and what does not, contact Excello Digital. We help European businesses close exactly these kinds of overlooked gaps between the tools they trust and the tools sitting quietly next to them.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!