Description
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.
Published: 2026-08-28
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pocket through version 8.33.0.0 stores externally supplied HTML when the "Save to Pocket" feature is used. This content can contain JavaScript that is executed in the app’s web view. The script gains access to native bridge methods and can alter or hijack the application state, enabling attackers to execute code, exfiltrate data, or manipulate the user experience. The weakness is an XSS flaw that permits arbitrary script execution.

Affected Systems

Android Pocket application, package name com.ideashower.readitlater.pro, is affected in all releases up to 8.33.0.0. The product is End‑of‑Life with no available vendor patch. The application can be installed on Android devices, and the vulnerability remains exploitable while the app is present.

Risk and Exploitability

The CVSS score of 9.2 reflects a high severity and remote code execution risk. No EPSS score is reported, but with the app still in use, the exploitation probability is likely high. The vulnerability is not listed in the CISA KEV catalog, but the absence of a patch and end‑of‑life status elevate the risk. The likely attack vector is user interaction: an attacker supplies a malicious link to be saved via Pocket, triggering the injected JavaScript in the web view. Once executed, the script can invoke native bridge methods to modify app behavior or exfiltrate data.

Generated by OpenCVE AI on August 28, 2026 at 14:43 UTC.

Remediation

Vendor Solution

The only mitigation is uninstallation of the application.


Vendor Workaround

Immediately uninstall com.ideashower.readitlater.pro from all Android devices. Revoke Google OAuth grants associated with the Pocket account. No vendor-provided mitigation or patch is available. Product is End-of-Life.


OpenCVE Recommended Actions

  • Immediately uninstall the Pocket app (com.ideashower.readitlater.pro) from all Android devices.
  • Revoke any Google OAuth grants associated with the Pocket account to remove any lingering authorization tokens.
  • Delete all local Pocket data, clear caches, and remove any saved URLs or content that may contain malicious HTML before considering re‑installing an alternative solution.

Generated by OpenCVE AI on August 28, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Untrusted HTML Injection in Pocket Allows XSS with Native Bridge Exploitation

Fri, 28 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T03:36:23.687Z

Reserved: 2026-08-28T03:36:23.090Z

Link: CVE-2026-82090

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T05:16:47.400

Modified: 2026-08-28T05:16:47.400

Link: CVE-2026-82090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T14:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')