It turned out that same add-on could read almost everything else you did in that browser.
This month, researchers at Guardio Labs disclosed a flaw in the Adobe Acrobat browser extension, tracked as CVE-2026-48294. On a vulnerable version, simply landing on the wrong web page was enough for that page to reach through the extension and pull what you had open elsewhere: your WhatsApp Web chats, your contacts, whatever you happened to be signed into. No password, no malware, no attachment. Just the page and an extension you already trusted. Adobe fixed it over a single weekend, and there is no sign anyone used it in the wild.
One PDF tool is the smaller story. Browser extensions sit inside the same window your staff use for email, banking, and every business account, and many are allowed to read and change everything on every site they touch. A 2025 study by LayerX found that ninety-nine percent of employees run at least one extension, more than half run one with high or critical access to their data, and one in five now run an AI-powered extension asking for that same reach. Almost none of it is watched by anyone. The access we hand these tools is the exposure.
The fix is not to tear them all out. It is to know what you have. Pull the list of extensions running across your team, look hard at anything that can read and change all your data on every site, and clear out what nobody actually uses, starting with the finance and admin accounts that have the most to lose. Keep whatever survives that cut updated. An extension you have not thought about in a year is still reading over your shoulder every day.
The most dangerous tool on your computer is usually the one you forgot you installed.
NexusTek is a CMMC L2-certified managed service provider serving small and mid-sized businesses across the United States.