Executive brief
The Adobe Acrobat extension for the Google Chrome web browser is affected by a security vulnerability that could allow an attacker to access sensitive session information. This occurs when a user is tricked into visiting a malicious website or interacting with a compromised page while the extension is active. An exploit could lead to the theft of login sessions or other private data handled by the browser.
Technical details
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier contain a Universal Cross-Site Scripting (UXSS) vulnerability. The flaw is classified as a cross-origin data disclosure issue, where improper neutralization of input during web page generation (CWE-79) allows an attacker to bypass the Same-Origin Policy. Exploitation requires a remote attacker to entice a victim into visiting a maliciously crafted URL or interacting with a compromised web page. Successful exploitation allows the attacker to gain unauthorized access to session-related data across different origins. Adobe has addressed this in later versions of the extension.
Affected products
- Adobe Acrobat PDF Extension (Chrome) Up to and including 26.5.2.2
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory