Skip to content
KitploitKITPLOIT
HerramientasBlog
Log in
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day — CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE published | Kitploit
Herramientas/GitHubGitHub/funfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day
Android SecurityVulnerability ScannersiOS SecurityVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityMobile SecurityPapers & Research

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Learning & Education
GitHubfunfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day

CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE published

Ver Repositorio
3132hace 19 díasAún no revisado
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.
ChatGPT Image 13 set 2026, 16_09_06 # XSS 0-Click / 0-Day Vulnerability Report

CVE CVSS Status CNA Tag

Cross-Site Scripting (0-Click) Leading to JavaScript Bridge Abuse in Pocket Android & iOS — CVSS 9.2 CRITICAL

CVE-2026-82090 — Published by MITRE Corporation (2026-08-28)

Author: Ing. Zampier Zago (FUNFACTOR1) Division: Section 1 — Department of Cyber Security, PS 1978 Limited Contact: [email protected] Web: www.ps1978ltd.it Classification: Security Vulnerability Analysis — CVE-2026-82090


Dual-Use Content Disclaimer: This repository contains a vulnerability analysis and a Proof of Concept (PoC) for an End-of-Life (EOL) product. The information and code provided are strictly for educational purposes, defensive analysis, and official CVE documentation. The author holds no responsibility for any misuse of this information.


https://github.com/user-attachments/assets/e2b0aa46-df64-452b-afbf-fa31dd8c650d

1. Executive Summary

A DOM-based Cross-Site Scripting (XSS) vulnerability has been confirmed in Pocket Android version 8.33.0.0 (package com.ideashower.readitlater.pro), the final release shipped by Mozilla / Read It Later, Inc. before service termination in July 2025. The vulnerability allows an attacker to inject and execute arbitrary JavaScript in the application's WebView without any user interaction beyond a single "Save to Pocket" action — a 0-click exploit post-delivery.

The root cause is the unsanitized injection of externally-sourced HTML content directly into the DOM via jQuery's .html() method ($(document.body).html(content)), in the asset-bundled file assets/html/j/articleview-mobile.js (lines 95–99). Content is fetched and rendered automatically in the background by com.pocket.sdk.offline.DownloadingService with no user interaction required.

The application also exposes a native Java-to-JavaScript bridge (PocketAndroidArticleInterface), registered via addJavascriptInterface and confirmed in classes2.dex, callable by JavaScript executing within the WebView.

Vendor disclosure record: The XSS was formally reported to Mozilla Security on 2024-07-10 with CWE-79 classification and full technical detail. Mozilla acknowledged receipt on 2024-07-11 and explicitly declined to remediate, declaring Pocket out of scope. Mozilla subsequently released v8.33.0.0 in 2025 with the vulnerable code entirely unchanged. Forensic analysis of v8.33.0.0 confirms the identical vulnerable call at lines 95–99 of articleview-mobile.js.

Lineage: The same identical line — $(document.body).html(content), in a file of the same name articleview-mobile.js — is present in the iOS counterpart bundle ReadItLaterPro.app (Pocket iOS v4.5.2), dating to the era immediately preceding the April 17, 2012 rebrand of Read It Later as Pocket. The CVE covers all versions from v0 through v8.33.0.0 — the defect has been continuously shipped, unmodified, across the product's entire 18-year lifespan (see §7). Forensic code-level confirmation via the oldest available bundle (iOS v4.5.2) dates the identical sink to at least 2012.

No patch is available. The product is abandoned. All installed instances remain permanently vulnerable.

FieldValue
CVECVE-2026-82090 — Published 2026-08-28 — CNA: MITRE Corporation
Vulnerability typeDOM-Based XSS (0-click) + JavaScript Bridge Abuse
CWECWE-79, CWE-116
Exploit status0-click, 0-day — no patch available; product End-of-Life
Vendor response2024-07-11 — "Pocket is out of scope" (Frida, Mozilla Security Team)
Affected productPocket Android v8.33.0.0 (final release)
Package IDcom.ideashower.readitlater.pro
VendorMozilla Corporation / Read It Later, Inc.
CVSS v4.0 Score9.2 — CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SeverityCRITICAL
First reported to vendor2021-04-19 (paywall bypass)
XSS formally reported to Mozilla Security2024-07-10
Final APK released with vulnerability intact2025 — v8.33.0.0
Service sunset2025-07-08
Code lineage18 years — all versions (v0 → v8.33.0.0, 2007 → 2025). Forensic code confirmation from 2012 iOS bundle.

2. Affected Product

  • Product name: Pocket — Save. Read. Grow. (Android)
  • Package name: com.ideashower.readitlater.pro
  • Build version: 8.33.0.0 (final release before service sunset)
  • APK analyzed: com.ideashower.readitlater.pro_8.33.0.0.apk
  • Vendor: Read It Later, Inc. / Mozilla Corporation
  • Google Play: Unpublished from Google Play Store on 2025-05-21. Listing page may still be reachable at https://play.google.com/store/apps/details?id=com.ideashower.readitlater.pro but the app is no longer available for download.
  • Service status: TERMINATED (2025-07-08). The application remains installed on millions of devices with no forced uninstall, kill-switch, or security update deployed. Video evidence (2026-01-02) confirms full operation — including paywall bypass and background services — months after official shutdown.

3. Vulnerability Details — Issue #1: 0-Click XSS via WebView

3.1 Vulnerability Classification

FieldValue
TypeDOM-Based Cross-Site Scripting
CWECWE-79 — Improper Neutralization of Input During Web Page Generation
Secondary CWECWE-116 — Improper Encoding or Escaping of Output
Attack vectorRemote, 0-click (zero user interaction post-delivery)
Privileges requiredNone
ScopeChanged — WebView context crosses trust boundary into native Android bridge

3.2 Vulnerable Component

File: assets/html/j/articleview-mobile.js Lines 95–99:

// article content was retrieved
loadCallback : function(content)
{
    // TODO : 3.0 : If file was missing, handle that correctly
    $(document.body).html(content);

Root cause: Externally-sourced HTML is passed directly to jQuery 3.4.1's .html() method with no sanitization. jQuery 3.4.1 executes embedded <script> tags and inline event handlers (onerror, onload). No call to DOMPurify, sanitize(), escapeHtml(), or equivalent exists anywhere in the 1,836-line file. The content variable originates from the Java layer without JS-side filtering.

The // TODO : 3.0 : If file was missing, handle that correctly comment immediately preceding the vulnerable call demonstrates the code was never production-hardened. This comment was present in every version of the app through the final release v8.33.0.0.

3.3 JavaScript Bridge Evidence

File: assets/html/j/articleview-mobile.js, lines 11–14:

// Android comm object
if (typeof PocketAndroidArticleInterface == 'undefined')
    PocketAndroidArticleInterface = false;

isAndroid = !!PocketAndroidArticleInterface;

Confirmed via DEX string analysis (classes2.dex):

PocketAndroidArticleInterface
setJavaScriptEnabled
addJavascriptInterface

Confirmed bridge methods from JS call sites: onReady(), onError(), onScrollChanged(), setFrozen(), placePageBlockers(), toggleFullscreen(), setViewType(), scrollToPosition(), onTextSearch(), onRequestedHighlightPatch(), updatePageSwipingDisabledAreas(), getHorizontalMargin(), getMaxMediaHeight(), isConnected().

3.4 Background Sync Service

AndroidManifest.xml confirms:

Descargar herramienta