Security Flaw in Adobe Chrome Extension Exposed WhatsApp Web Data
Israeli cybersecurity firm Guardio discovered a critical vulnerability in the Adobe Acrobat Reader extension for Chrome, installed on over 300 million computers worldwide. The flaw allowed attackers to access sensitive information from WhatsApp Web, including chat lists, contact names, profile pictures, visible messages, and one-time digital codes. These codes could potentially enable breaches of other accounts such as Instagram and Facebook.
The attack did not require hacking WhatsApp directly, stealing passwords, or installing malware. Instead, it relied on victims clicking a malicious link that appeared legitimate, which could be delivered via SMS, email, WhatsApp, Slack, Microsoft Teams, or even Google ads. Once the link was opened, the vulnerability could be exploited within less than a second through the compromised extension.
Guardio reported the issue to Adobe through a responsible disclosure process. Adobe confirmed the findings, promptly fixed the vulnerability within days, and released a security update to users. There have been no reports of actual exploitation or affected users so far.
Guardio's research highlights the growing attack surface in an era of multiple tools, browser extensions, and AI systems with broad data access. Guardio’s research head, Nati Tal, emphasized that attackers often target the weakest link in the environment rather than the primary service. He also noted that advanced AI models accelerate vulnerability discovery, which can be a double-edged sword if such tools fall into the wrong hands. Guardio’s AI-driven research system identified the flaw within hours of the vulnerable extension’s release on the Chrome Web Store.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.