« All posts

HermeticReader (CVE-2026-48294): Three Chrome Extension Bugs in WhatsApp Web

Three vulnerabilities in Adobe's Acrobat Chrome extension led to a data exfiltration chain in WhatsApp Web. This incident serves as a critical reminder for engineers.

According to a technical breakdown by Guardio Labs published on July 22, Adobe's Acrobat Chrome extension introduced a WhatsApp Web integration engine ('Hermes') in April. Three distinct vulnerabilities combined to create a full DOM exfiltration chain. These flaws included an unauthenticated storage write accessible from any web-accessible resource, a service worker that fails to check the sender, and a monotonically-incrementing tab ID counter used to predict WhatsApp's tab ID. Adobe quickly patched the issue in version 26.5.2.3 over a weekend.