PatchSiren cyber security CVE debrief
CVE-2026-48294 Adobe CVE debrief
The Adobe Acrobat PDF Extension for Chrome, versions 26.5.2.2 and earlier, contains a UXSS-class cross-origin data disclosure vulnerability (CVE-2026-48294). This High-severity issue (CVSS score of 7.4) allows attackers to gain access to victim session data by exploiting user interaction, such as visiting malicious URLs or interacting with compromised web pages. Scope change occurs due to successful exploitation. Users and administrators should take immediate action to mitigate potential risks.
- Vendor
- Adobe
- Product
- Adobe Acrobat PDF Extension (Chrome)
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-29
Who should care
Users of Adobe Acrobat PDF Extension for Chrome, particularly those with sensitive data access, should be aware of this vulnerability. IT administrators and cybersecurity teams responsible for managing browser extensions and protecting against user interaction-based threats should prioritize patching and mitigation efforts.
Technical summary
The vulnerability, tracked as CVE-2026-48294, affects Adobe Acrobat PDF Extension for Chrome versions 26.5.2.2 and earlier. It is classified as a UXSS-class cross-origin data disclosure issue. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N, indicating a High severity level. The vulnerability requires user interaction for exploitation, such as visiting a maliciously crafted URL or interacting with a compromised web page.
Defensive priority
High
Recommended defensive actions
- Update Adobe Acrobat PDF Extension for Chrome to the latest version.
- Restrict user access to sensitive data and web pages.
- Implement robust browser extension management policies.
- Conduct regular security audits and vulnerability assessments.
- Educate users about safe browsing practices and potential risks.
- Monitor for suspicious user interactions and anomalous behavior.
- Consider implementing a Web Application Firewall (WAF) to detect and prevent attacks.
Evidence notes
The information provided is based on data from official sources, including the CVE record and NVD detail pages. The CVE was published on 2026-06-17T10:55:01.660Z and modified on 2026-06-17T16:58:37.447Z. The vulnerability affects Adobe Acrobat PDF Extension for Chrome versions 26.5.2.2 and earlier.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48294 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48294
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48294 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48294
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://chromewebstore.google.com/detail/adobe-acrobat-pdf-edit-co/efaidnbmnnnibpcajpcglclefindmkaj
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.