Overview
- Guardio researchers discovered and reported the chained vulnerability chain called HermeticReader to Adobe and the issue was published in coverage on Wednesday, July 22, 2026.
- The bug exploited an internal extension HTML resource and a service worker that accepted commands from any page, allowing a single visit to write to the extension’s storage and flip a feature flag that activates the Hermes integration engine.
- Once Hermes was enabled the extension could inject a form into a WhatsApp Web tab and cause the browser to post the rendered DOM, exposing chat lists, contact names, profile names, and visible message text without needing credentials or malware.
- Adobe fixed the flaw in Acrobat Chrome extension version 26.5.2.3 and pushed the update automatically, and Guardio reports no public evidence of active exploitation, but users should verify they have the patched version or disable the extension if unused.
- The vulnerability mattered because the extension has a very large install base of roughly 300–329 million browsers, showing how insecure cross-origin messaging and service-worker trust can create broad exposure for web session data.