CVE-2026-48294
Adobe Adobe Acrobat PDF Extension (Chrome), acrobat
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
- CVSS
- 7.4
- EPSS
- 1.91% 77.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.17