Affected Systems
Adobe Acrobat extension for Chrome versions 26.5.2.1 and below. Affects approximately 329 million browser installations. Exploitation requires victim to visit attacker-controlled webpage while extension is installed and WhatsApp Web is in use.
Exploitation Status
No active exploitation observed. Vulnerability discovered by Guardio Labs four hours after Adobe introduced it via update. Patched within two days of disclosure. No public PoC released.
Business Impact
Attackers could exfiltrate WhatsApp Web conversations, contact names, chat lists, and profile data from rendered sessions without authentication or user interaction beyond visiting a malicious site. No session cookies required. Secondary risk: account hijacking via QR code substitution (requires user action). High exposure due to massive install base, but rapid patch deployment and lack of observed exploitation reduce immediate risk.
Urgency
🟠Within 24 hours
Recommended Actions
- Verify Adobe Acrobat Chrome extension is updated to version 26.5.2.3 or later across all endpoints (chrome://extensions in browser)
- Audit Chrome extension deployment via enterprise policy (Google Workspace Admin Console or GPO) to confirm automatic updates are enabled
- Review web proxy and DNS logs for unusual form submissions or data exfiltration from WhatsApp Web domains during the vulnerability window (post-26.5.2.1 release)
- Educate users on risks of visiting untrusted websites while authenticated to sensitive web applications like WhatsApp Web
- Consider implementing browser isolation or extension allowlisting policies for high-risk user groups
