CVE-2026-48294
Awaiting Analysis Awaiting Analysis - Queue
UXSS Vulnerability in Adobe Acrobat PDF Extension for Chrome

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Adobe Systems Incorporated

Description
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
adobe acrobat_pdf_extension 26.5.2.2
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier. It is a UXSS-class cross-origin data disclosure vulnerability, meaning an attacker can exploit it to access data related to the victim's session across different origins. To exploit this vulnerability, the attacker needs the victim to interact with a maliciously crafted URL or a compromised web page.

Impact Analysis

The vulnerability can lead to unauthorized disclosure of sensitive session data to an attacker. This could compromise the victim's privacy and security by exposing information that should be restricted to the user's session. Since the scope is changed, the impact extends beyond the vulnerable component, potentially affecting other parts of the user's browsing experience.

Mitigation Strategies

The vulnerability affects Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier. Since exploitation requires user interaction with a maliciously crafted URL or compromised web page, immediate mitigation steps include updating the Adobe Acrobat PDF Extension to a version later than 26.5.2.2 if available.

Additionally, educating users to avoid clicking on suspicious links or visiting untrusted websites can reduce the risk of exploitation.

Compliance Impact

The vulnerability in Adobe Acrobat PDF Extension (Chrome) allows an attacker to gain access to data regarding the victim's session through a UXSS-class cross-origin data disclosure. This type of data exposure could potentially lead to unauthorized access to personal or sensitive information.

Such unauthorized data disclosure may impact compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access and breaches.

However, exploitation requires user interaction, such as visiting a malicious URL or interacting with a compromised web page, which may influence the risk assessment under these standards.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48294. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart