Affected Systems

Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) versions up to and including 26.5.2.2. Affects 314+ million users. Exploitation impacts any web application data accessible in victim's browser, demonstrated against WhatsApp Web.

Exploitation Status

Patched by Adobe. No evidence of active exploitation disclosed. Proof-of-concept demonstrated by Guardio Labs researchers. Requires user interaction (visiting malicious URL or compromised page).

Business Impact

Universal cross-site scripting (UXSS) vulnerability allows attackers to bypass same-origin policy and read session-bound data from any web application in victim's browser. Demonstrated attack extracts WhatsApp Web chat lists, contact names, messages, and profile data without credential theft or malware installation. Attack surface includes any user with Adobe Acrobat extension who visits attacker-controlled page. No authentication bypass or cookie theft required—extension's Hermes engine manipulates DOM to exfiltrate rendered page content.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Update Adobe Acrobat Chrome extension to version 26.5.2.3 or later immediately via Chrome Web Store (chrome://extensions)
  • Audit browser extension inventory across enterprise endpoints and enforce automatic extension updates via Chrome Enterprise policy
  • Review web proxy and DNS logs for suspicious iframe activity targeting extension resource URLs (chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/*)
  • Educate users on risks of clicking unfamiliar links, especially from search results or marketing emails, when high-privilege extensions are installed
  • Consider implementing Chrome Enterprise policy to restrict extension permissions or disable Adobe Acrobat extension until patching is verified