CVE-2026-82090 Overview
CVE-2026-82090 is a cross-site scripting (XSS) vulnerability in the Pocket application through version 8.33.0.0. The flaw exists in the "Save to Pocket" feature, which injects external HTML directly into the Document Object Model (DOM). Attacker-controlled JavaScript can execute in the application context and alter application state through native bridge methods. The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation).
Critical Impact
Attackers can execute arbitrary JavaScript in the Pocket application, manipulate saved content, and invoke native bridge methods that alter application state on affected mobile devices.
Affected Products
- Pocket application versions through 8.33.0.0
- Pocket Android client (per public proof-of-concept)
- "Save to Pocket" HTML rendering component
Discovery Timeline
- 2026-08-28 - CVE-2026-82090 published to NVD
- 2026-08-28 - Last updated in NVD database
Technical Details for CVE-2026-82090
Vulnerability Analysis
The vulnerability resides in the Pocket application's "Save to Pocket" workflow. The feature retrieves external HTML content from saved URLs and injects it into the DOM without adequate sanitization. Because the rendered content is treated as trusted, embedded <script> payloads and event handlers execute inside the application's WebView context.
Execution inside the WebView is significant because Pocket exposes native bridge methods to JavaScript. Attacker-controlled scripts can invoke these bridges to modify application state, access saved article data, and pivot deeper into the mobile application. The public proof-of-concept describes a zero-click chain on Android, meaning victim interaction beyond saving a malicious link is not required.
Root Cause
The root cause is improper output encoding when rendering third-party HTML fetched during the save operation. The application inserts remote markup into the DOM without stripping active content, and the WebView permits JavaScript execution alongside a JavaScript-to-native bridge. This combination converts a content-rendering flaw into a state-manipulation primitive.
Attack Vector
An attacker hosts a page containing malicious HTML and JavaScript. When a victim saves that URL to Pocket, or when a crafted link is delivered to a targeted account, the application fetches and renders the payload. The injected script executes with the privileges of the Pocket WebView and calls exposed native bridge methods. Refer to the public proof-of-concept repository for technical details of the exploitation chain.
Detection Methods for CVE-2026-82090
Indicators of Compromise
- Unexpected outbound network requests from the Pocket application to attacker-controlled domains after saving a URL.
- Presence of <script> tags, inline event handlers, or obfuscated JavaScript in saved article payloads stored locally by Pocket.
- Anomalous invocation patterns of Pocket native bridge methods recorded in mobile telemetry.
Detection Strategies
- Inspect saved-article cache and WebView storage on managed Android devices for HTML containing active content.
- Correlate mobile proxy logs with Pocket save events to identify domains delivering executable HTML payloads.
- Monitor for Pocket application versions at or below 8.33.0.0 across the mobile fleet using MDM inventory data.
Monitoring Recommendations
- Ingest mobile device telemetry and WebView logs into a centralized analytics platform to correlate save events with suspicious script execution.
- Alert on Pocket application installations that have not been upgraded past 8.33.0.0.
- Track outbound DNS and HTTP requests from mobile endpoints for known attacker infrastructure referenced in the public proof-of-concept.
How to Mitigate CVE-2026-82090
Immediate Actions Required
- Upgrade the Pocket application to a version later than 8.33.0.0 on all managed mobile devices.
- Instruct users to avoid saving untrusted URLs to Pocket until patches are deployed.
- Enforce mobile application version compliance through Mobile Device Management (MDM) policies.
Patch Information
No vendor advisory URL was provided in the NVD record at publication. Administrators should track the vendor's release channels and update Pocket beyond version 8.33.0.0 when a fixed release is available. Reference the GitHub proof-of-concept for technical background while monitoring for the official fix.
Workarounds
- Restrict use of the "Save to Pocket" feature on high-risk accounts until a patched build is installed.
- Block known malicious domains at the network egress and mobile DNS layers to reduce delivery of hostile payloads.
- Apply MDM policy to disable Pocket on devices that cannot be updated past 8.33.0.0.
# Example MDM compliance check: flag devices running vulnerable Pocket versions
adb shell dumpsys package com.ideashower.readitlater.pro | grep versionName
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.