What is CVE-2026-48294?
CVE-2026-48294 is a critical flaw in the Adobe Acrobat Chrome extension (314M+ users) that allows a malicious webpage to read WhatsApp Web chats, contact names, chat previews, and profile data without requiring malware, stolen credentials, or session cookies. Users should immediately update or disable the extension until a patch is applied.
Azərbaycanca: CVE-2026-48294 Adobe Acrobat-ın Chrome genişləndirilməsində (314 milyon+ istifadəçi) aşkarlanmış kritik zəiflikdir. Təcavüzkar sadəcə zərərli veb-səhifəyə girişlə WhatsApp Web söhbətlərini, kontakt adlarını və profil məlumatlarını heç bir zərərli proqram və ya sessiya çərəzləri olmadan oxuya bilər. İstifadəçilər dərhal genişləndirməni yeniləməli və ya rəsmi patch yayımlanana qədər deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What impact does CVE-2026-48294 have on the Adobe Acrobat Chrome extension?
This critical flaw allows an attacker to read WhatsApp Web chats, contact names, chat previews, and profile data simply by tricking a user into visiting a malicious webpage, without requiring any malware, stolen credentials, or session cookies.
What should users do to protect themselves from CVE-2026-48294?
Users should immediately update the Adobe Acrobat Chrome extension or temporarily disable it until an official patch is applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.