Affected Systems

Adobe Acrobat extension for Google Chrome (specific versions not disclosed). Users with both the extension installed and active WhatsApp Web sessions are at risk.

Exploitation Status

Exploitation method disclosed; no CVE assigned yet. Active exploitation status unknown. Malicious websites can trigger unauthorized access to WhatsApp Web data without user authentication.

Business Impact

High-severity privacy breach risk. Attackers can access private WhatsApp conversations, contacts, and messages through browser-based exploitation. No authentication required once user visits malicious site. Particularly concerning for organizations using WhatsApp Business for customer communications or internal coordination. No CVSS score published yet.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Immediately disable or remove Adobe Acrobat extension from Chrome browsers across the organization until patch is confirmed
  • Audit Chrome extension inventory using Chrome Browser Cloud Management or GPO to identify affected installations
  • Block installation of Adobe Acrobat Chrome extension via Chrome Enterprise policy (ExtensionInstallBlocklist) until vendor issues security update
  • Monitor web proxy logs for unusual access patterns to web.whatsapp.com from corporate networks
  • Educate users about risks of visiting untrusted websites while logged into WhatsApp Web or other sensitive web applications