The security vulnerability in the Adobe Acrobat Chrome extension enables attackers to interfere with the extension's internal operations from any website. This flaw, named 'HermeticReader,' arises from the combination of three distinct weaknesses. Attackers can trigger the extension's WhatsApp integration to manipulate the DOM structure of the user's WhatsApp Web page, thereby exfiltrating data such as messages, contact lists, and profile information.
The vulnerability operates without requiring session credentials; it only requires that users have installed the extension and opened WhatsApp Web. Attackers can inject a form into the WhatsApp page to redirect its content to their own servers. However, messages that have not been loaded or viewed cannot be captured in this attack.
Adobe fixed this issue in version 26.5.2.3 and provided automatic updates for users. Security researchers praised Adobe for patching the flaw within two days of being notified. Users are advised to verify that their extensions are updated to the latest version.
