news.mlab.sh
Back to the feed
vulnerability

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

High
Summary

A widely-used Adobe Chrome extension was exploited to steal WhatsApp data by tricking users into visiting a malicious webpage. The vulnerability, dubbed HermeticReader, allowed attackers to silently access users' private chats and contacts without requiring any malware or compromised credentials. Adobe swiftly patched the issue, highlighting a UXSS-class cross-origin data disclosure vulnerability.

A popular Adobe Chrome extension, used by approximately 329 million browsers, was found to be vulnerable to a data theft attack. Researchers at Guardio discovered and reported the issue to Adobe. The attack, named HermeticReader, did not involve exploiting a WhatsApp vulnerability or deploying malware. Instead, it leveraged a UXSS-class cross-origin data disclosure vulnerability within the Adobe extension’s internal messaging system.

Specifically, an attacker could trick users into visiting a seemingly harmless webpage, which would then load a hidden frame. This frame tricked the extension into accepting unverified commands, allowing the attacker to write to the extension’s local storage and activate Hermes, a dormant integration engine built by Adobe. Hermes then bridged the gap to WhatsApp Web, enabling the attacker to invisibly scrape the victim’s private chats, contacts, and account details in plain text. Adobe released a patch for the vulnerability in June. The vulnerability was assigned CVE-2026-48294.

Guardio has published a video demonstrating the HermeticReader attack in action. This incident is related to a previous bounty paid to Meta for a vulnerability exposing customer support data.

Read the full article at SecurityWeek