Researchers at Guardio Labs discovered a vulnerability (named HermeticReader) in the official Adobe Acrobat extension for Chrome—one of the most widely used extensions in the world, with approximately 300 million installations. The vulnerability allowed a malicious website to bypass the normal separation between browser tabs and, if the victim also had WhatsApp Web open, to read their private conversations. No virus, stolen password, or compromised account was needed—all it took was for the user to land on the wrong page.
The good news is that there's no need to panic: Adobe fixed the flaw the very same weekend it was reported, and the fix was automatically pushed to computers through the Chrome Web Store. Those who discovered the issue say they haven't seen any actual attacks.
The lesson for a small business isn’t about this specific flaw, but about a habit. A browser extension runs with access to almost everything you do in the browser: email, web apps, WhatsApp Web, even online banking. A single faulty extension or one abandoned by its developer becomes a door left wide open. A few simple checks greatly reduce the risk:
- Keep your browser up to date and leave automatic updates turned on—that’s how the fix mentioned above made its way onto computers.
- Delete any extensions you no longer use; every extra extension is an additional attack vector.
- Check what permissions your remaining extensions are requesting, and be cautious with those that ask for “access to data from all websites.”
For a company without an in-house IT department, the simplest step is to periodically review the browser extensions on work computers—five minutes that close a door that many often leave open.
The analyses and reports on which this article is based:
- BleepingComputer | https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
- Guardio Labs | https://guard.io/labs/hermeticreader---the-vulnerability-that-turned-adobe-300m-install-extension-into-a-full-whatsapp-takeover
This article was generated with AI assistance.