CVE-2026-82090

Summary

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

Affected Software

VendorProductVersion RangeStatus
getpocketPocket0 <= 8.33.0.0affected

Weaknesses

  • CWE-79: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Workarounds

Immediately uninstall com.ideashower.readitlater.pro from all Android devices.

Revoke Google OAuth grants associated with the Pocket account.

No vendor-provided mitigation or patch is available. Product is End-of-Life.

References