
If you use Google Chrome and have the Adobe Acrobat extension installed, a recently fixed flaw — dubbed HermeticReader and tracked as CVE-2026-48294 — could have let any website you visited silently read your WhatsApp Web messages. Researchers at Guardio Labs discovered that the extension’s broad permissions gave it unintended access to WhatsApp Web’s interface, meaning a malicious page could capture your chat list, contact names, message previews, and the text of any open conversation — without ever asking for permission.
The good news is that Adobe patched the flaw quickly and pushed the fix automatically to all users. You don’t need to download anything manually; Chrome extensions update in the background. No evidence of real-world attacks using this technique has been reported, but the researchers stress that the attack required nothing more than visiting a specially crafted website while the vulnerable extension was active.
How to check if you’re affected
Affected versions of the Adobe Acrobat Chrome extension are 26.5.2.1 and earlier. To confirm you have the patched version:
- Open Chrome and go to
chrome://extensionsin the address bar. - Find Adobe Acrobat in the list and click Details.
- Look for a version number — you should see 26.5.2.3 or later.
If your version is older than 26.5.2.3, click the three-dot menu in Chrome → Help → About Google Chrome to trigger an update check, which will also refresh your extensions.
