ZeroHour

CVE-2026-82090

PoC mass

DOM XSS in Pocket (through 8.33.0.0) via 'Save to Pocket' HTML injection

CVSS 4.0
9.2 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

Pocket (the save-for-later service and its app) versions through 8.33.0.0 are vulnerable to cross-site scripting (CWE-79): the 'Save to Pocket' feature injects external HTML fetched with saved content directly into the app's DOM without sufficient sanitization. An attacker who controls that external content - for example via a crafted page or resource that gets saved - can have arbitrary JavaScript executed inside the app's web context. The injected JavaScript can then invoke native bridge methods to alter the application's state, producing high impact on the confidentiality, integrity, and availability of the app and its data (CVSS 4.0 base score 9.2, critical). All users running Pocket at or below version 8.33.0.0 are affected; the vector indicates no privileges are required, though exploitation depends on specific conditions (attack requirements present). There is no known exploitation in the wild: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS is 0.3% (20th percentile).

What to do: Update Pocket to the first release after 8.33.0.0 as soon as a patched version is published (no fixed version is documented in the available data); until then, avoid saving pages from untrusted or attacker-influenced sources and monitor for a vendor advisory. Given the absence of a public PoC, no KEV listing, and EPSS of 0.3%, prioritize this as important but not urgent.

Affected
Pocket (Mozilla) Pocket app ('Save to Pocket' feature)all versions through and including 8.33.0.0; no fixed version specified in the advisory data
Estimated exposure
mass≈ millions of app users (Pocket historically showed 10M+ Google Play downloads) — Estimated from Pocket's large consumer install base - the mobile app has historically listed 10M+ Google Play downloads and the service reported tens of millions of users - though the current number of devices still running 8.33.0.0 or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods.

Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.