Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The only mitigation is uninstallation of the application.
Vendor Workaround
Immediately uninstall com.ideashower.readitlater.pro from all Android devices. Revoke Google OAuth grants associated with the Pocket account. No vendor-provided mitigation or patch is available. Product is End-of-Life.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/FUNFACTOR1/pocket-android-xss-0click-cve |
|
Fri, 28 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getpocket
Getpocket pocket |
|
| Vendors & Products |
Getpocket
Getpocket pocket |
Fri, 28 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Untrusted HTML Injection in Pocket Allows XSS with Native Bridge Exploitation |
Fri, 28 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-28T16:17:06.780Z
Reserved: 2026-08-28T03:36:23.090Z
Link: CVE-2026-82090
Updated: 2026-08-28T16:16:59.114Z
Status : Received
Published: 2026-08-28T05:16:47.400
Modified: 2026-08-28T20:20:14.833
Link: CVE-2026-82090
No data.
OpenCVE Enrichment
Updated: 2026-08-28T16:12:56Z