Overview
- Security researchers at Guardio disclosed on July 23 that a chain of flaws in the Adobe Acrobat Chrome extension’s Hermes feature let a crafted webpage access the visible contents of another user’s WhatsApp Web session without any clicks or installs.
- The exploit worked because the extension did not properly check the origin of messages and allowed a webpage to trigger Hermes, then used an invisible HTML form to make WhatsApp Web send its rendered page content to an attacker-controlled server.
- Researchers said the attack only captured rendered chat content such as contact names, chat lists and message text and did not grab raw session cookies or passwords, but visible messages could include sensitive items like two-factor codes.
- Adobe received a private report from Guardio and released a patched extension the same weekend, and users should verify automatic updates or manually install the fixed Acrobat Chrome extension to eliminate the immediate risk.
- The incident highlights a broader security lesson: small origin-check and integration errors across popular browser extensions can combine into high-impact privacy failures and should prompt tighter review of widely used add-ons and third-party web integrations.