Vulnerabilities · 54 days ago

Browser Extension Breaks WhatsApp Web Isolation

A browser add-on built for PDFs can become part of the trust boundary for every other tab in that profile. Here, the broken assumption is isolation: a site does not need WhatsApp credentials if an extension can read what WhatsApp Web has already loaded in the browser session.

The flaw affects the Adobe Acrobat Chrome extension and lets arbitrary websites access WhatsApp Web conversations and data without authentication. The issue is tracked as CVE-2026-48294.

The risk sits in the browser session, not in WhatsApp alone. If an extension can inspect page content, patching the web app does not close that path, because the extension still sees the authenticated session rendered on screen.

CVE-2026-48294

NVD KEV

CVSS 7.4 HIGH: adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. EPSS 2% (78th percentile).

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-23

Editions

Related stories