Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

Summary

A vulnerability in an Adobe extension, with over 300 million installations, allowed attackers to steal WhatsApp messages and contacts. Exploitation only required convincing a user to visit a malicious website.

IFF Assessment

FOE

The vulnerability allows for the theft of sensitive user data, representing a win for attackers and a loss for defenders.

Severity

8.8 High (AI Estimated)

The vulnerability has a high impact due to the potential for sensitive data exfiltration (confidentiality and integrity) and a high exploitability due to the low attack complexity and lack of privileges required.

Defender Context

This incident highlights the significant risks associated with browser extensions, even those from reputable vendors like Adobe, due to their potential access to user data and web content. Defenders should prioritize auditing and monitoring the security of extensions used within their organizations and educating users about the dangers of clicking on malicious links that could trigger such exploits.

Read Full Story →