ShellCodeX Intelligence Brief
HIGH
Vulnerabilities
Adobe extension flaw with millions of installs enabled WhatsApp data theft
Source headline: Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
A vulnerability in an Adobe extension allowed attackers to steal WhatsApp data. The attacker’s primary method was persuading a victim to visit a malicious website. Once the user was lured, WhatsApp messages and contacts could be exfiltrated. The issue affected the ecosystem because the extension had a very large install base. Users should avoid untrusted links and review Adobe extension permissions and installed components.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
SecurityWeek
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
Open original source