Unrated severityNVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026
CVE-2026-48294
CVE-2026-48294
Description
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=26.5.2.2
Patches
Vulnerability mechanics
References
1News mentions
7- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News · Jul 27, 2026
- WhatsApp Web chats exposed by Adobe’s Acrobat extension flawMalwarebytes Labs · Jul 23, 2026
- Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million UsersCyber Security News · Jul 22, 2026
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web DataThe Hacker News · Jul 22, 2026
- Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data TheftSecurityWeek · Jul 22, 2026
- Adobe Chrome extension flaw let sites access private WhatsApp chatsBleepingComputer · Jul 22, 2026
- Adobe: Five CVEs Across DNG SDK and Chrome PDF Extension Disclosed June 16Vypr Intelligence · Jun 16, 2026