A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage. The bug is classified as a universal cross-site scripting (UXSS) issue with a CVSS score of 7.4, allowing a malicious site to bypass the browser’s same-origin policy and read data tied to a victim’s active session in another tab. This vulnerability affects every version of the Adobe Acrobat PDF Extension for Chrome up to and including 26.5.2.2, an extension installed on roughly 314–329 million browsers worldwide. The flaw is particularly concerning as it highlights the growing risk in the browser-extension ecosystem where individually minor flaws can combine into a full account-compromise chain, especially in extensions with hundreds of millions of installs. The attack unfolds by exploiting Chrome’s sequential tab-numbering system to predict the numeric tab ID and manipulate the page’s DOM, ultimately injecting a hidden form into WhatsApp Web’s page and submitting it to the attacker’s server, exposing on-screen rendered text content. This case underscores the importance of verifying installed extension versions are current and highlights the need for more secure message-passing, storage validation, and feature-flag logic in browser extensions.
We recommend you to update Adobe Acrobat PDF Extension for Chrome to version 26.5.2.3.[/subscribe_to_unlock_form]
A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage. The bug is classified as a universal cross-site scripting (UXSS) issue with a CVSS score of 7.4, allowing a malicious site to bypass the browser’s same-origin policy and read data tied to a victim’s active session in another tab. This vulnerability affects every version of the Adobe Acrobat PDF Extension for Chrome up to and including 26.5.2.2, an extension installed on roughly 314–329 million browsers worldwide. The flaw is particularly concerning as it highlights the growing risk in the browser-extension ecosystem where individually minor flaws can combine into a full account-compromise chain, especially in extensions with hundreds of millions of installs. The attack unfolds by exploiting Chrome’s sequential tab-numbering system to predict the numeric tab ID and manipulate the page’s DOM, ultimately injecting a hidden form into WhatsApp Web’s page and submitting it to the attacker’s server, exposing on-screen rendered text content. This case underscores the importance of verifying installed extension versions are current and highlights the need for more secure message-passing, storage validation, and feature-flag logic in browser extensions.
We recommend you to update Adobe Acrobat PDF Extension for Chrome to version 26.5.2.3.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]