Impact
Pocket through version 8.33.0.0 stores externally supplied HTML when the "Save to Pocket" feature is used. This content can contain JavaScript that is executed in the app’s web view. The script gains access to native bridge methods and can alter or hijack the application state, enabling attackers to execute code, exfiltrate data, or manipulate the user experience. The weakness is an XSS flaw that permits arbitrary script execution.
Affected Systems
Android Pocket application, package name com.ideashower.readitlater.pro, is affected in all releases up to 8.33.0.0. The product is End‑of‑Life with no available vendor patch. The application can be installed on Android devices, and the vulnerability remains exploitable while the app is present.
Risk and Exploitability
The CVSS score of 9.2 reflects a high severity and remote code execution risk. No EPSS score is reported, but with the app still in use, the exploitation probability is likely high. The vulnerability is not listed in the CISA KEV catalog, but the absence of a patch and end‑of‑life status elevate the risk. The likely attack vector is user interaction: an attacker supplies a malicious link to be saved via Pocket, triggering the injected JavaScript in the web view. Once executed, the script can invoke native bridge methods to modify app behavior or exfiltrate data.
OpenCVE Enrichment