Close Menu
    What's Hot

    Trump’s Plan for Science: More Money for A.I., Less for Universities

    After shocking quarter, IBM insists that AI isn’t killing the mainframe

    Clarity Act Mired In Debate Over Whether to Bar President From Selling Crypto

    Facebook X (Twitter) Instagram
    Trending
    • Trump’s Plan for Science: More Money for A.I., Less for Universities
    • After shocking quarter, IBM insists that AI isn’t killing the mainframe
    • Clarity Act Mired In Debate Over Whether to Bar President From Selling Crypto
    • Kinder Morgan, Inc. (KMI) Q2 2026 Earnings Call Transcript
    • What Visuals Show About Recent Damage to U.S. Military Sites in the Middle East
    • Aaron Finch labels English cricket a ‘circus’ after Ben Stokes and Brendon McCullum’s exits and says Australians are ‘laughing’ | Cricket News
    • Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
    • Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

    adminBy adminJuly 22, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 22, 2026Vulnerability / Browser Security

    Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

    Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data.

    The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability described as a case of universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability. It affects all versions of the extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) prior to and including 26.5.2.2.

    Successful exploitation of the flaw can bypass the browser’s same-origin policy and access data linked to the victim’s session across origins. The only prerequisite is that it requires user interaction. A victim must be convinced into visiting a maliciously crafted URL or interact with a compromised web page that triggers the extension’s vulnerable code path.

    Cybersecurity

    In other words, an attacker can weaponize the flaw to obtain cross-origin read access to session-bound data. This can include authenticated content from third-party web applications loaded in the victim’s browser.

    “The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.,” Guardio Labs researcher Shaked Biner said in a report shared with The Hacker News. “The visitor, who already has the Adobe Acrobat extension installed, opens that page.”

    “The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view – the chat list, contact names, messages, the profile name, the text of whatever conversation is open – the whole WhatsApp in the attacker’s hands.”

    What’s notable about the flaw is that it does not require a bad actor to install malware through some other means, phish a user’s credentials, or extract their session cookie. All it needs is for the victim to visit the crafted web page.

    The entire sequence of actions is as follows –

    • An attacker-controlled page calls an iframe element loaded from the extension resources.
    • The iframe sends commands to alter settings to activate the Hermes engine, which handles WhatsApp integration in the extension only if a specific feature flag is enabled (“floodgate-add”).
    • The attacker page opens WhatsApp Web in a browser tab in the background.
    • The iframe sends commands directly to the engine directed against the WhatsApp tab after obtaining the tab’s numeric ID.
    • The engine manipulates WhatsApp Web’s by injecting a POST form into WhatsApp’s DOM to steal WhatsApp data.

    “Why does submitting a form carry chat text out of WhatsApp’s origin? Two enablers deep from the HTML specifications: An option element with no value attribute submits its text content – and the text content of a node is the concatenation of everything rendered beneath it,” Biner explained. “Move the live body in, and the option’s submitted value becomes the entire rendered page text!”

    Cybersecurity

    “The second enabler is that WhatsApp Web’s content security policy that ships no form-action directive, and per the spec that absence means a top-level form submission may navigate to any origin. So WhatsApp itself performs the navigation, POSTing its own rendered DOM to our controlled endpoint and then dutifully rendering whatever we send back.”

    As a result, a threat actor can exploit HermeticReader to capture the rendered chat list, contact names, message previews, the profile name, and the visible text of the open conversation.

    “The industry pours its attention into the dramatic exploit classes and leaves the plumbing to the assumption that nobody will ever look hard at it,” Guardio concluded. “Composition is the threat. Plumbing-level flaws compose into building-level collapse, and the bigger the install base, the longer the building stands before anyone checks the joints.”

    Acrobat Adobe data extension flaw malicious read sites web WhatsApp
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleAdobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
    Next Article Aaron Finch labels English cricket a ‘circus’ after Ben Stokes and Brendon McCullum’s exits and says Australians are ‘laughing’ | Cricket News
    admin
    • Website

    Related Posts

    What Visuals Show About Recent Damage to U.S. Military Sites in the Middle East

    July 22, 2026

    Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

    July 22, 2026

    GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

    July 22, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Trump’s Plan for Science: More Money for A.I., Less for Universities

    After shocking quarter, IBM insists that AI isn’t killing the mainframe

    Clarity Act Mired In Debate Over Whether to Bar President From Selling Crypto

    Kinder Morgan, Inc. (KMI) Q2 2026 Earnings Call Transcript

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by