Summary
Adobe patched a high-severity vulnerability dubbed HermeticReader (CVE-2026-48294) in its Acrobat Chrome extension that allowed malicious websites to silently steal WhatsApp Web chat data and contacts.
Take Action:
If you use the Adobe Acrobat extension in Chrome, open your browser's extensions page and confirm it is running version 26.5.2.3 or later. Adobe already pushed the fix automatically, so most users are covered, but do verify yourself. If you can't confirm the version, remove the extension until you can verify. If you use WhatsApp Web on that browser, log out and re-link your device to invalidate any session an attacker could have touched.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)