mimile
mimile.ai
Back to feed
This event is part of a larger story
Массовые утечки и атаки: июль 2026 года
Read briefing

Adobe Chrome extension flaw exposed WhatsApp data of 300M users

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Adobe Chrome extension flaw exposed WhatsApp data of 300M users

A vulnerability in Adobe's Chrome extension, installed on 329 million browsers, allowed attackers to steal WhatsApp chats and contacts. Security firm Guardio discovered the flaw, dubbed HermeticReader, and reported it to Adobe, which patched it in June. The exploit required no malware or compromised credentials, only a malicious webpage.

The Vulnerability

The flaw, tracked as CVE-2026-48294, is a UXSS-class cross-origin data disclosure vulnerability in the Adobe Acrobat Chrome extension. Guardio researchers found that the extension's internal messaging system lacked security checks, allowing a malicious webpage to inject unverified commands via a hidden frame. This enabled attackers to silently write to the extension's local storage and activate a dormant integration engine called Hermes.

Attack Mechanism

Once Hermes was activated, it bridged the extension to WhatsApp Web, allowing the attacker to scrape private chats, contacts, and account details in plain text. The attack, named HermeticReader, did not involve any WhatsApp vulnerability, malware, or access to the victim's device. Guardio demonstrated the exploit in a published video, showing how a user visiting a harmless-looking page could have their data stolen.

Patch and Impact

Adobe patched the vulnerability in June 2026 shortly after Guardio's disclosure. The extension has approximately 329 million installations, making it one of the most widely used Chrome extensions. Guardio advised users to ensure their extension is updated to the latest version to mitigate the risk.

What's Next

Adobe has released a patch, but users must manually update the extension or enable auto-updates. It remains unclear how many users were affected before the fix was deployed.

1 source

Adobe Chrome extension flaw exposed WhatsApp data of 300M users