type: cve ยท created: 2026-07-23 ยท updated: 2026-07-23 ยท tags: [cve, uxss, extension, chrome, adobe, browser] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government, healthcare, finance] ยท au_impact: true
CVE-2026-48294 โ HermeticReader: Adobe Acrobat Chrome Extension UXSS
CVE-2026-48294 (CVSS 7.4) is a universal cross-site scripting (UXSS) vulnerability in the Adobe Acrobat Chrome extension, disclosed by Guardio Labs as HermeticReader. The flaw affects approximately 314 million users and allows malicious websites to bypass the browser's same-origin policy, potentially reading data from services like WhatsApp Web.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-48294 |
| CVSS | 7.4 (High) |
| Type | Universal XSS (UXSS) โ same-origin policy bypass |
| Product | Adobe Acrobat Chrome Extension |
| Affected users | ~314 million |
| Impact | Cross-origin data access (WhatsApp Web data demonstrated) |
| Prerequisite | User interaction โ victim must visit a malicious URL |
| Disclosed by | Guardio Labs |
| Disclosure date | 2026-07-22 |
Attack Vector
The vulnerability allows a malicious website to bypass Chrome's same-origin policy through a flaw in the Adobe Acrobat extension's permissions/extension context handling. Guardio Labs demonstrated reading WhatsApp Web data as a proof of concept.
Mitigation
- Apply the extension update from the Chrome Web Store once available
- Disable or restrict the Adobe Acrobat Chrome extension where not strictly necessary
- Exercise caution when visiting untrusted URLs while the extension is active
Related Pages
- Cve 2026 50522 Sharepoint Server Rce โ SharePoint RCE (another critical vulnerability under active exploitation)