WhatsApp Web Users Urged To Check Chrome Extension After Adobe Security Flaw
Adobe has patched a Chrome extension flaw that could have exposed WhatsApp Web chats to malicious websites. Users are urged to check their extension version.
Anyone who keeps WhatsApp Web open on a work or home computer is being advised to check one browser setting, after researchers revealed a flaw in Adobe's Acrobat extension for Chrome that could have allowed a malicious website to quietly read private conversations. Adobe has already fixed it and the update installs automatically, but researchers say it is worth confirming.
The flaw, named HermeticReader by the team that found it, is tracked as CVE-2026-48294. It was uncovered by Guardio Labs and affects the Adobe Acrobat PDF Extension for Chrome, which Guardio says sits on roughly 329 million browsers worldwide.
What made it unusual is how little the attacker needed. There was no malware to install, no usernames or passwords to steal, and no bug in WhatsApp itself. The weakness sat entirely in the Adobe extension, which runs with far more privilege than an ordinary website and was tricked into acting on instructions it should have refused.
A victim needed to be logged into WhatsApp Web, or have a WhatsApp Web tab sitting open, with the vulnerable Adobe extension installed and enabled in Chrome or another Chromium-based browser. Where that was the case, a single visit to a specially built page could give an attacker sight of the chat list, contact names, the profile name, message previews, and the visible text of whichever conversation was open at the time.
Malwarebytes, which covered the research in its security newsletter, likened the effect to handing a visitor "a master key that opened every apartment in the building" rather than just the one they were invited into.
Adobe's response drew praise from the researchers. The company acknowledged the report, built a fix, and shipped it across a single weekend, with the CVE record published on 17 June 2026. Guardio has said it saw no indication the flaw was ever actively exploited, and that its researchers spotted the problem within hours of an Adobe update to the extension in early June.
The Irish relevance is straightforward. WhatsApp runs through daily life here, from family and school groups to GAA club committees, community alert groups, and small businesses taking orders and bookings. The Digital News Report Ireland 2026, launched in Cork on 16 June 2026 by Coimisiún na Meán, found that 27% of Irish respondents had used WhatsApp in the previous week to find, read, watch, share, or discuss news, second only to Facebook on 33%.
Ireland also sits at the centre of how WhatsApp is regulated across Europe. WhatsApp Ireland Limited is the Dublin-based data controller for users in the European Union, which makes the Irish Data Protection Commission the lead supervisory authority for the service across the bloc. Adobe's Irish subsidiary, Adobe Systems Software Ireland Limited, is registered in Saggart, County Dublin.
The National Cyber Security Centre had not listed this flaw on its alerts and advisories page as of 27 July 2026. The page does carry an earlier NCSC advisory on a WhatsApp verification code scam.
Adobe fixed the problem in version 26.5.2.3 of the extension, and versions 26.5.2.2 and earlier are affected. Chrome updates extensions automatically for most people, so most machines will already be covered, though some setups delay or block automatic updates.
To check your own:
- Type chrome://extensions into the Chrome address bar and press enter.
- Switch on Developer mode using the toggle in the top right corner, which reveals version numbers.
- Find the Adobe Acrobat entry and confirm the version is 26.5.2.3 or later.
- If it is older, open the Chrome menu, choose Extensions, then Manage Extensions, and click Update. Restart Chrome and check the version again.
Two further steps are worth taking regardless. In WhatsApp, open Settings and then Linked devices, and log out of anything you do not recognise or no longer use. And remove any browser extension you do not use, do not recognise, or do not trust, because an extension you never open still runs with every permission you granted it.
The wider point is about extensions in general. They sit in a privileged position between a user and every website they visit, and a convenience feature bolted on to a trusted brand can quietly become a privacy risk. Each individual mistake here was small. It was the stacking of them that mattered.
Guardio Labs, the cybersecurity firm that discovered the flaw:
"Composition is the threat."