Summary
A critical vulnerability (CVE-2026-48294) in the Adobe Acrobat Chrome extension, dubbed "HermeticReader," could allow hackers to access private WhatsApp Web chats. If a user with the vulnerable extension opens a malicious landing page while WhatsApp Web is active, attackers could exploit a cross-site scripting flaw to steal chat content. Adobe has since patched the issue in version 26.7.2.0.