A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage no clicks, downloads, or credential theft required. Security researchers at Guardio Labs uncovered the flaw, dubbed “HermeticReader,” and officially tracked as CVE-2026-48294 with a CVSS score of 7.4. The bug is classified as a universal cross-site scripting (UXSS) issue that lets a malicious site bypass the browser’s same-origin policy and read data tied to a victim’s active session in another tab. HermeticReader (Source: Guardio) It affects every version of the Adobe Acrobat PDF Extension for Chrome up to...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!