🔐 CVE Alert

CVE-2026-82090

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

CWE CWE-79
Vendor getpocket
Product pocket
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for getpocket pocket

Be the first to know when new unknown vulnerabilities affecting getpocket pocket are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

getpocket / Pocket
0 ≤ 8.33.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/FUNFACTOR1/pocket-android-xss-0click-cve