Sign in to baba News

The Desk, the news read to you every hour, is part of News Plus.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Adobe Chrome Extension Flaw Exposed WhatsApp Web Data, Now Fixed

By דיגיטל
Translated & summarized from Mako by baba
The story · English

Israeli cybersecurity firm Guardio discovered a critical vulnerability in the Adobe Acrobat Reader extension for the Chrome browser, which is installed on over 300 million computers worldwide. The flaw allowed attackers to access sensitive information from WhatsApp Web, including chat lists, contact names, profile pictures, on-screen messages, and one-time digital codes. These codes could potentially enable breaches of additional accounts such as Instagram and Facebook.

The attack scenario demonstrated by Guardio did not require hacking WhatsApp directly, stealing passwords, or installing malware. Instead, it relied on victims clicking a malicious link that appeared legitimate, which could be delivered via SMS, email, WhatsApp messages, Slack, Microsoft Teams, or even through sponsored Google search results. Once the link was opened, the vulnerability in the Adobe extension could be exploited within less than a second to access WhatsApp Web data in the same browser.

Guardio reported the vulnerability to Adobe through a responsible disclosure process. Adobe confirmed the findings, promptly fixed the security flaw within days, and released an update to users, making the exploit no longer possible. There have been no reports of users being harmed by this vulnerability.

Guardio’s research head, Nati Tal, emphasized how the proliferation of tools, browser extensions, and AI systems with direct access to personal data expands the attack surface for cybercriminals. He noted that attackers often target the weakest link in the surrounding environment rather than the primary service itself. Tal also highlighted that advanced AI models, like those from Anthropic, enable rapid and extensive code vulnerability searches, which can be a double-edged sword if such tools fall into the wrong hands. Guardio’s AI-driven research system identified the flaw within hours of the vulnerable extension’s release on the Chrome Web Store.

Read the original at Mako
Full coverage · 2 outlets
100% centerFirst: Mako · Jul 22

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 2
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Ask About This Article

Duki reads it, and every newsroom on the same story, then answers with sources.

Open the live terminal