CVE-2026-82090: XSS
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Pocket through 8.33.0.0from your environment.Uninstall the Pocket application (v8.33.0.0) because the only provided mitigation for the XSS issue is removal.
Event History
Frequently Asked Questions
What user interaction is required for exploitation?
The issue is described as occurring through the "Save to Pocket" functionality and is characterized in the reference as a zero-click XSS issue. No additional user interaction requirements are provided.
What can injected JavaScript do in the affected application?
Injected JavaScript can alter Pocket's application state through native bridge methods. The provided information does not specify which state changes or bridge methods are available.