Cross-Origin Data Disclosure Vulnerability in Adobe Acrobat PDF Extension for Chrome
CVE-2026-48294

7.4HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
16 June 2026

Badges

πŸ“ˆ Score: 132πŸ‘Ύ Exploit ExistsπŸ“° News Worthy

What is CVE-2026-48294?

CVE-2026-48294 is a cross-origin data disclosure vulnerability found in the Adobe Acrobat PDF Extension for Chrome, specifically affecting versions 26.5.2.2 and earlier. Adobe Acrobat serves as a widely used tool for viewing, creating, and managing PDF documents, which are crucial for both personal and professional communications. This vulnerability poses a risk as it allows attackers to potentially access sensitive information related to the victim's session. Exploitation requires user interaction, as the victim must either visit a malicious link or engage with a compromised web page. This user dependency adds a layer of complexity to the attack method, but it also makes it crucial for users to be vigilant in their online activities, as falling for such traps can lead to dire consequences.

Potential impact of CVE-2026-48294

  1. Data Exposure: The primary impact of this vulnerability is the unauthorized disclosure of sensitive session data, which can lead to further exploitation of user accounts or personal information.

  2. Increased Attack Surface: By exploiting this vulnerability, attackers can gain footholds in organizations, leading to lateral movement within networks and increasing the potential for broader breaches.

  3. User Trust Erosion: Successful exploits can compromise user trust in the software and its ability to protect sensitive information, potentially damaging the reputation of Adobe and leading to decreased user adoption.

Affected Version(s)

Adobe Acrobat PDF Extension (Chrome) 0 <= 26.5.2.2

News Articles

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats.

2 days ago

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Adobe patched CVE-2026-48294 after malicious pages could abuse its Acrobat Chrome extension to expose rendered WhatsApp Web chat data.

2 days ago

Adobe Chrome extension flaw let sites access private WhatsApp chats

The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication.

2 days ago

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.