Security researchers report a vulnerability in the Adobe Acrobat Chrome extension that could allow websites to access private WhatsApp Web chat content. According to the accounts from both outlets, the issue involves a cross-site scripting/class cross-origin data disclosure weakness affecting a widely used Chrome extension. The flaw is described as being capable of exposing conversations and other data displayed in WhatsApp Web within the browser. Researchers say the problem does not require the usual authentication steps to obtain access to the rendered WhatsApp Web content in the affected context, meaning a malicious site could potentially retrieve data that should remain private. The reports characterize the behavior as improper cross-origin access and data disclosure tied to the extension’s handling of WhatsApp Web pages. Both sources frame the issue as a security risk for users who have the extension installed and are using WhatsApp Web in the same browser environment.