Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-23 ยท updated: 2026-07-23 ยท tags: [cve, uxss, extension, chrome, adobe, browser] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government, healthcare, finance] ยท au_impact: true

CVE-2026-48294 โ€” HermeticReader: Adobe Acrobat Chrome Extension UXSS

CVE-2026-48294 (CVSS 7.4) is a universal cross-site scripting (UXSS) vulnerability in the Adobe Acrobat Chrome extension, disclosed by Guardio Labs as HermeticReader. The flaw affects approximately 314 million users and allows malicious websites to bypass the browser's same-origin policy, potentially reading data from services like WhatsApp Web.

Vulnerability Details

Attribute Detail
CVE CVE-2026-48294
CVSS 7.4 (High)
Type Universal XSS (UXSS) โ€” same-origin policy bypass
Product Adobe Acrobat Chrome Extension
Affected users ~314 million
Impact Cross-origin data access (WhatsApp Web data demonstrated)
Prerequisite User interaction โ€” victim must visit a malicious URL
Disclosed by Guardio Labs
Disclosure date 2026-07-22

Attack Vector

The vulnerability allows a malicious website to bypass Chrome's same-origin policy through a flaw in the Adobe Acrobat extension's permissions/extension context handling. Guardio Labs demonstrated reading WhatsApp Web data as a proof of concept.

Mitigation

  1. Apply the extension update from the Chrome Web Store once available
  2. Disable or restrict the Adobe Acrobat Chrome extension where not strictly necessary
  3. Exercise caution when visiting untrusted URLs while the extension is active

Related Pages