<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cross-Site Scripting on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/cross-site-scripting/</link><description>Recent content in Cross-Site Scripting on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 25 Jul 2026 12:13:24 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/cross-site-scripting/index.xml" rel="self" type="application/rss+xml"/><item><title>HermeticReader Turned Adobe Acrobat Into a WhatsApp Spy on 329 Million Browsers</title><link>https://hackingpassion.com/hermeticreader-adobe-whatsapp-flaw/</link><pubDate>Sat, 25 Jul 2026 12:13:24 +0200</pubDate><guid>https://hackingpassion.com/hermeticreader-adobe-whatsapp-flaw/</guid><description>&lt;p>An Adobe extension on roughly &lt;strong>329 million&lt;/strong> browsers had a flaw the researchers named &lt;strong>HermeticReader&lt;/strong>, and it let any web page you opened read your WhatsApp Web. The chat list, the contact names, the conversation you had open, all of it lifted off the screen while you did nothing but land on the page. 🧐&lt;/p>
&lt;p>There was no malware. Nothing landed on your machine, nothing was downloaded. Your password stayed untouched, your session cookie too. WhatsApp itself had no bug. The attacker needed no Adobe account and no way onto your computer. You opened a page that looked like a search result or a link in an email, and that was enough.&lt;/p></description></item></channel></rss>