Browser Extension Breaks WhatsApp Web Isolation

A browser add-on built for PDFs can become part of the trust boundary for every other tab in that profile. Here, the broken assumption is isolation: a site does not need WhatsApp credentials if an extension can read what WhatsApp Web has already loaded in the browser session. The flaw affects the Adobe Acrobat Chrome extension and lets arbitrary websites access WhatsApp Web conversations and data without authentication. The issue is tracked as CVE-2026-48294. The risk sits in the browser session, not in WhatsApp alone. If an extension can inspect page content, patching the web app does not close that path, because the extension still sees the authenticated session rendered on screen.

Part of the PlainSec briefing for 2026-07-23

Sources