- Guardio Labs found a serious vulnerability chain CVE-2026-48294 in the Adobe Acrobat Chrome extension, which enabled hackers to obtain WhatsApp Web data without leaving a trace.
- The attack activated a dormant Hermes integration engine to inject a POST form into the WhatsApp Web DOM. This forced the browser to transmit chat logs and contacts to an attacker’s server.
- Adobe released a patch in version 26.5.2.3 within two days of receiving the report, so users should check their extension for any updates to stay safe.
Researchers at Guardio Labs found a major security flaw in the widely used Chrome extension of Adobe Acrobat. They noted that cybercriminals can siphon the private conversations, contact lists, and profile information from compromised WhatsApp Web sessions of users due to a technical issue. Over 314 million active extension installations worldwide faced potential exposure to this silent data harvesting attack.
The vulnerability chain was dubbed by security experts as HermeticReader and given the official code CVE-2026-48294. The vulnerability received 7.4 points on the CVSS scale – this means that it falls under the serious category. Also, the vulnerable software encompasses all the releases of the browser extension up to version 26.5.2.2.
An attack needs a simple user interaction in the hacked web environment. The victim just has to open a malicious website while already having an active WhatsApp Web tab open. The exploitation happens silently without any need for two-factor authentication, password phishing, or session cookie theft.
Understanding the HermeticReader Attack Chain
When a user visits a malicious website, actions in the background automatically begin on the web server side. The page embeds an internal iframe resource originating directly from the browser extension directory. This internal page sends configuration commands that alter local application settings and wake up a dormant integration module known as the Hermes engine.
The extension relies on background service worker scripts to handle internal communication between open web pages and browser APIs. Weak message validation inside this communication system allows untrusted external scripts to pass commands to internal extension handlers. The background worker fails to check message origin properties before executing requests.
The attacker activates this hidden Hermes integration by setting an internal configuration switch called floodgate-add. Once the system enables this setting, the malicious site opens WhatsApp Web in a background browser tab. The external script calculates the sequential numeric tab identifier assigned by Chrome to target the active WhatsApp session accurately.
Specifically, the script sends privileged commands directly to the Hermes engine to control the target tab. The engine alters the underlying page structure by injecting a custom POST form into the WhatsApp DOM.
Rather than reading the chat text directly, the script forces WhatsApp Web to transmit its rendered content to an attacker-controlled server. Consequently, the web application sends its own page text straight to the remote endpoint.
HTML specifications allow a form element with an empty option tag to submit its rendered text content automatically. The injected form captures every visible text element rendered within the active chat window.
Furthermore, WhatsApp Web lacks a restrictive form-action policy directive inside its content security rules. The absence of this security rule permits top-level form submissions to navigate to external third-party servers freely.
Exposed WhatsApp Data and Account Hijacking Risks
The HermeticReader attack exposes extensive amounts of private personal information to remote attackers. The exfiltrated dataset includes complete contact lists, message previews, profile names, and open chat logs. Anything visible on the victim’s screen during the active session flows to the external server immediately.
The risks of WhatsApp data exposure underscore the importance of enhanced security, WhatsApp is bringing fingerprint authentication to Android users. Unloaded chats or unrendered messages remain safe from exfiltration because the exploit targets visible DOM elements. Moreover, the researchers presented the second attack scenario that utilizes QR codes for connecting devices.
In this case, the attacker can substitute the legitimate QR code for logging into WhatsApp with a fake link on the page. In turn, the attacker gets complete control over the whole WhatsApp account if a user scans the replaced QR code.
This secondary takeover scenario requires additional user action, making simple chat exfiltration the primary threat. The attack poses significant privacy risks for corporate employees using WhatsApp Web for business communications. Malicious actors could harvest sensitive corporate discussions and confidential client details silently.
Furthermore, the vulnerability combines three minor flaws inside the extension’s internal messaging pipeline. Individual security flaws appear minor when isolated, but combining these weaknesses creates a dangerous cross-origin data disclosure chain. The exploit bypasses standard browser same-origin policy enforcement to grant attackers full control over active web tabs.
Browser extensions operate with elevated execution privileges to deliver user features across multiple web domains. A single flaw in extension message handling breaks the security isolation between unrelated websites. Usually, cybercriminals will act on these elevated permissions to turn trusted browser add-ons into tools that will collect data silently.
Rapid Patch Deployment and Defense Recommendations
Guardio Labs discovered the software flaw four hours after Adobe shipped the integration update. The research group used an automated AI code platform to unpack and analyze 344 obfuscated JavaScript files. The analysis system highlighted newly introduced attack paths across the extension codebase quickly.
Automated analysis tools help security researchers identify newly exposed attack surfaces immediately after software releases. Comparing code updates enables threat hunting teams to validate security flaws before cybercriminals find them. Human researchers validated the HermeticReader exploit chain end-to-end to confirm the potential impact.
Guardio private researchers reported the vulnerability chain directly to the Adobe security response team. Adobe acknowledged the vulnerability report immediately and produced a working software patch within two days over a weekend; this rapid vendor response prevented widespread exploitation across the global user base.
Adobe resolved the flaw by releasing version 26.5.2.3 through the official Chrome Web Store. The Chrome browser updates extensions automatically for most users worldwide.
Users can verify their software safety by opening the internal extension management page at chrome://extensions. Checking that the browser runs version 26.5.2.3 or higher ensures complete protection against HermeticReader attacks.
Organizations managing enterprise browser fleets should enforce automated extension update policies across all user endpoints. Disabling unneeded browser extensions reduces total attack surfaces across corporate IT environments. Security teams must monitor extension permissions to protect sensitive web applications from cross-origin data theft.
The HermeticReader vulnerability highlights the growing security risks associated with complex browser extensions. As developers add rich integrations to popular extensions, they introduce potential entry points for malicious web pages.
Also, software vendors must apply rigorous message validation controls across all internal communication channels. Notably, proactive security research and rapid patch deployment remain essential for protecting millions of internet users daily.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
South Korea Telecom Data Breaches Drive More Customers to Switch Carriers
A fresh study links South Korea’s telecom data breaches to a jump in customers changing carrie...
StopAndProtect Hijacks 2,000 WordPress Sites to Spread Malware and Ransomware
A new malware operation called StopAndProtect hijacks WordPress sites to build hidden command center...
Firefox Users on iOS Can Now Block Ads without an Extension
Mozilla is slowly rolling out a built-in ad blocker for Firefox on iPhones and iPads, no extension n...
Suspected Chinese Hackers Exploit Critical VMware vCenter Flaw Across 47 Countries
Several servers across 47 countries record a compromise via an exploit of Vmware vCenter directory-t...
WhatsApp Tests On-Device Scam Alert without Reading User Messages
WhatsApp is testing a new tool called Scam Alert that spots scam messages right on your phone. The t...
Apple Faces Lawsuit Over Claims that iCloud Private Relay Leaks User IP Addresses
A law firm sued Apple, saying its Private Relay tool did not protect user privacy as promised. Exper...