Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan

    July 23, 2026

    Modi vows ‘stringent punishment’ for exam fraud fuelling India’s youth-led ‘Cockroach’ protests

    July 23, 2026

    Stühlerücken in der Union: Wer folgt auf Thorsten Frei? – POLITICO

    July 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan
    • Modi vows ‘stringent punishment’ for exam fraud fuelling India’s youth-led ‘Cockroach’ protests
    • Stühlerücken in der Union: Wer folgt auf Thorsten Frei? – POLITICO
    • Ann Widdecombe: Family announces public memorial later this year
    • Business rates to be cut by 20% for pubs, clubs and music venues in England | Business rates
    • ServiceNow bets $40 million on Indian banking software specialist to expand its financial services push
    • Anthropic Releases Claude Security Plugin for Claude Code in Beta: A Multi-Agent Vulnerability Scanner That Runs in Your Terminal
    • Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Thursday, July 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 23, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 22, 2026Vulnerability / Browser Security

    Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data.

    The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability described as a case of universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability. It affects all versions of the extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) prior to and including 26.5.2.2.

    Successful exploitation of the flaw can bypass the browser’s same-origin policy and access data linked to the victim’s session across origins. The only prerequisite is that it requires user interaction. A victim must be convinced into visiting a maliciously crafted URL or interact with a compromised web page that triggers the extension’s vulnerable code path.

    Cybersecurity

    In other words, an attacker can weaponize the flaw to obtain cross-origin read access to session-bound data. This can include authenticated content from third-party web applications loaded in the victim’s browser.

    “The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.,” Guardio Labs researcher Shaked Biner said in a report shared with The Hacker News. “The visitor, who already has the Adobe Acrobat extension installed, opens that page.”

    “The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view – the chat list, contact names, messages, the profile name, the text of whatever conversation is open – the whole WhatsApp in the attacker’s hands.”

    What’s notable about the flaw is that it does not require a bad actor to install malware through some other means, phish a user’s credentials, or extract their session cookie. All it needs is for the victim to visit the crafted web page.

    The entire sequence of actions is as follows –

    • An attacker-controlled page calls an iframe element loaded from the extension resources.
    • The iframe sends commands to alter settings to activate the Hermes engine, which handles WhatsApp integration in the extension only if a specific feature flag is enabled (“floodgate-add”).
    • The attacker page opens WhatsApp Web in a browser tab in the background.
    • The iframe sends commands directly to the engine directed against the WhatsApp tab after obtaining the tab’s numeric ID.
    • The engine manipulates WhatsApp Web’s by injecting a POST form into WhatsApp’s DOM to steal WhatsApp data.

    “Why does submitting a form carry chat text out of WhatsApp’s origin? Two enablers deep from the HTML specifications: An option element with no value attribute submits its text content – and the text content of a node is the concatenation of everything rendered beneath it,” Biner explained. “Move the live body in, and the option’s submitted value becomes the entire rendered page text!”

    Cybersecurity

    “The second enabler is that WhatsApp Web’s content security policy that ships no form-action directive, and per the spec that absence means a top-level form submission may navigate to any origin. So WhatsApp itself performs the navigation, POSTing its own rendered DOM to our controlled endpoint and then dutifully rendering whatever we send back.”

    As a result, a threat actor can exploit HermeticReader to capture the rendered chat list, contact names, message previews, the profile name, and the visible text of the open conversation.

    “The industry pours its attention into the dramatic exploit classes and leaves the plumbing to the assumption that nobody will ever look hard at it,” Guardio concluded. “Composition is the threat. Plumbing-level flaws compose into building-level collapse, and the bigger the install base, the longer the building stands before anyone checks the joints.”

    Acrobat Adobe data Extension Flaw Malicious Read sites Web WhatsApp
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan

    GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

    New InfraTrust report reveals infrastructure flaws admins should patch first

    How enterprise GenAI can amplify ransomware risk — and how to contain it

    Attackers Combo Up Evasion Tactics for BEC Phishing

    Benchmark Raises Hut 8 Price Target After Bitcoin Miner Signs $9.8 Billion AI Data Center Deal

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan

    July 23, 2026

    Modi vows ‘stringent punishment’ for exam fraud fuelling India’s youth-led ‘Cockroach’ protests

    July 23, 2026

    Stühlerücken in der Union: Wer folgt auf Thorsten Frei? – POLITICO

    July 23, 2026

    Ann Widdecombe: Family announces public memorial later this year

    July 23, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    If you’ve heard online that London is dystopian and dangerous – read this. It just isn’t | Sadiq Khan

    July 23, 2026

    Modi vows ‘stringent punishment’ for exam fraud fuelling India’s youth-led ‘Cockroach’ protests

    July 23, 2026

    Stühlerücken in der Union: Wer folgt auf Thorsten Frei? – POLITICO

    July 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.