CVE-2026-82090
PoC massDOM XSS in Pocket (through 8.33.0.0) via 'Save to Pocket' HTML injection
Pocket (the save-for-later service and its app) versions through 8.33.0.0 are vulnerable to cross-site scripting (CWE-79): the 'Save to Pocket' feature injects external HTML fetched with saved content directly into the app's DOM without sufficient sanitization. An attacker who controls that external content - for example via a crafted page or resource that gets saved - can have arbitrary JavaScript executed inside the app's web context. The injected JavaScript can then invoke native bridge methods to alter the application's state, producing high impact on the confidentiality, integrity, and availability of the app and its data (CVSS 4.0 base score 9.2, critical). All users running Pocket at or below version 8.33.0.0 are affected; the vector indicates no privileges are required, though exploitation depends on specific conditions (attack requirements present). There is no known exploitation in the wild: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS is 0.3% (20th percentile).
What to do: Update Pocket to the first release after 8.33.0.0 as soon as a patched version is published (no fixed version is documented in the available data); until then, avoid saving pages from untrusted or attacker-influenced sources and monitor for a vendor advisory. Given the absence of a public PoC, no KEV listing, and EPSS of 0.3%, prioritize this as important but not urgent.
| Pocket (Mozilla) Pocket app ('Save to Pocket' feature) | all versions through and including 8.33.0.0; no fixed version specified in the advisory data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods.
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.