The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication.

The attack exploits a chain of vulnerabilities, collectively tracked as CVE-2026-48294 and dubbed HermeticReader by researchers at cybersecurity firm Guardio.

Exploiting them requires only that the target running the Adobe Acrobat extension be lured to a web page under the threat actor's control.

Stealing WhatsApp communications

The problem arises from the Adobe extension allowing any website to disguise attacker commands as internal extension messages, activate its WhatsApp integration, and redirect its privileged DOM operations into a WhatsApp tab with a predictable Tab ID.