CVE-2026-48294
CVSS 7.4 HIGH: adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. EPSS 2% (78th percentile).
Vulnerabilities · 54 days ago
A browser add-on built for PDFs can become part of the trust boundary for every other tab in that profile. Here, the broken assumption is isolation: a site does not need WhatsApp credentials if an extension can read what WhatsApp Web has already loaded in the browser session.
The flaw affects the Adobe Acrobat Chrome extension and lets arbitrary websites access WhatsApp Web conversations and data without authentication. The issue is tracked as CVE-2026-48294.
The risk sits in the browser session, not in WhatsApp alone. If an extension can inspect page content, patching the web app does not close that path, because the extension still sees the authenticated session rendered on screen.
CVSS 7.4 HIGH: adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. EPSS 2% (78th percentile).
3 sources covering this story
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Adobe patched CVE-2026-48294 after malicious pages could abuse its Acrobat Chrome extension to expose rendered WhatsApp Web chat data.
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.
Adobe Chrome extension flaw let sites access private WhatsApp chats
The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication.
Part of the PlainSec briefing for 2026-07-23