Adobe patched CVE-2026-48294 after malicious pages could abuse its Acrobat Chrome extension to expose rendered WhatsApp Web chat data.

The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication.

A Chrome extension made by Adobe was affected by a vulnerability that could have been exploited to steal a user’s WhatsApp data.