Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The only mitigation is uninstallation of the application.
Vendor Workaround
Immediately uninstall com.ideashower.readitlater.pro from all Android devices. Revoke Google OAuth grants associated with the Pocket account. No vendor-provided mitigation or patch is available. Product is End-of-Life.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/FUNFACTOR1/pocket-android-xss-0click-cve |
|
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getpocket
Getpocket pocket |
|
| Vendors & Products |
Getpocket
Getpocket pocket |
Fri, 28 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Untrusted HTML Injection in Pocket Allows XSS with Native Bridge Exploitation |
Fri, 28 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-28T03:36:23.687Z
Reserved: 2026-08-28T03:36:23.090Z
Link: CVE-2026-82090
No data.
Status : Received
Published: 2026-08-28T05:16:47.400
Modified: 2026-08-28T05:16:47.400
Link: CVE-2026-82090
No data.
OpenCVE Enrichment
Updated: 2026-08-28T16:12:56Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')