Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day — CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE published | Kitploit
도구/GitHubGitHub/funfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day
Android SecurityVulnerability ScannersiOS SecurityVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityMobile SecurityPapers & Research

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Learning & Education
GitHubfunfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day

CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE published

저장소 보기
313218일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.
ChatGPT Image 13 set 2026, 16_09_06 # XSS 0-Click / 0-Day Vulnerability Report

CVE CVSS Status CNA Tag

Cross-Site Scripting (0-Click) Leading to JavaScript Bridge Abuse in Pocket Android & iOS — CVSS 9.2 CRITICAL

CVE-2026-82090 — Published by MITRE Corporation (2026-08-28)

Author: Ing. Zampier Zago (FUNFACTOR1) Division: Section 1 — Department of Cyber Security, PS 1978 Limited Contact: [email protected] Web: www.ps1978ltd.it Classification: Security Vulnerability Analysis — CVE-2026-82090


Dual-Use Content Disclaimer: This repository contains a vulnerability analysis and a Proof of Concept (PoC) for an End-of-Life (EOL) product. The information and code provided are strictly for educational purposes, defensive analysis, and official CVE documentation. The author holds no responsibility for any misuse of this information.


https://github.com/user-attachments/assets/e2b0aa46-df64-452b-afbf-fa31dd8c650d

1. Executive Summary

A DOM-based Cross-Site Scripting (XSS) vulnerability has been confirmed in Pocket Android version 8.33.0.0 (package com.ideashower.readitlater.pro), the final release shipped by Mozilla / Read It Later, Inc. before service termination in July 2025. The vulnerability allows an attacker to inject and execute arbitrary JavaScript in the application's WebView without any user interaction beyond a single "Save to Pocket" action — a 0-click exploit post-delivery.

The root cause is the unsanitized injection of externally-sourced HTML content directly into the DOM via jQuery's .html() method ($(document.body).html(content)), in the asset-bundled file assets/html/j/articleview-mobile.js (lines 95–99). Content is fetched and rendered automatically in the background by com.pocket.sdk.offline.DownloadingService with no user interaction required.

The application also exposes a native Java-to-JavaScript bridge (PocketAndroidArticleInterface), registered via addJavascriptInterface and confirmed in classes2.dex, callable by JavaScript executing within the WebView.

Vendor disclosure record: The XSS was formally reported to Mozilla Security on 2024-07-10 with CWE-79 classification and full technical detail. Mozilla acknowledged receipt on 2024-07-11 and explicitly declined to remediate, declaring Pocket out of scope. Mozilla subsequently released v8.33.0.0 in 2025 with the vulnerable code entirely unchanged. Forensic analysis of v8.33.0.0 confirms the identical vulnerable call at lines 95–99 of articleview-mobile.js.

Lineage: The same identical line — $(document.body).html(content), in a file of the same name articleview-mobile.js — is present in the iOS counterpart bundle ReadItLaterPro.app (Pocket iOS v4.5.2), dating to the era immediately preceding the April 17, 2012 rebrand of Read It Later as Pocket. The CVE covers all versions from v0 through v8.33.0.0 — the defect has been continuously shipped, unmodified, across the product's entire 18-year lifespan (see §7). Forensic code-level confirmation via the oldest available bundle (iOS v4.5.2) dates the identical sink to at least 2012.

No patch is available. The product is abandoned. All installed instances remain permanently vulnerable.

FieldValue
CVECVE-2026-82090 — Published 2026-08-28 — CNA: MITRE Corporation
Vulnerability typeDOM-Based XSS (0-click) + JavaScript Bridge Abuse
CWECWE-79, CWE-116
Exploit status0-click, 0-day — no patch available; product End-of-Life
Vendor response2024-07-11 — "Pocket is out of scope" (Frida, Mozilla Security Team)
Affected productPocket Android v8.33.0.0 (final release)
Package IDcom.ideashower.readitlater.pro
VendorMozilla Corporation / Read It Later, Inc.
CVSS v4.0 Score9.2 — CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SeverityCRITICAL
First reported to vendor2021-04-19 (paywall bypass)
XSS formally reported to Mozilla Security2024-07-10
Final APK released with vulnerability intact2025 — v8.33.0.0
Service sunset2025-07-08
Code lineage18 years — all versions (v0 → v8.33.0.0, 2007 → 2025). Forensic code confirmation from 2012 iOS bundle.

2. Affected Product

  • Product name: Pocket — Save. Read. Grow. (Android)
  • Package name: com.ideashower.readitlater.pro
  • Build version: 8.33.0.0 (final release before service sunset)
  • APK analyzed: com.ideashower.readitlater.pro_8.33.0.0.apk
  • Vendor: Read It Later, Inc. / Mozilla Corporation
  • Google Play: Unpublished from Google Play Store on 2025-05-21. Listing page may still be reachable at https://play.google.com/store/apps/details?id=com.ideashower.readitlater.pro but the app is no longer available for download.
  • Service status: TERMINATED (2025-07-08). The application remains installed on millions of devices with no forced uninstall, kill-switch, or security update deployed. Video evidence (2026-01-02) confirms full operation — including paywall bypass and background services — months after official shutdown.

3. Vulnerability Details — Issue #1: 0-Click XSS via WebView

3.1 Vulnerability Classification

FieldValue
TypeDOM-Based Cross-Site Scripting
CWECWE-79 — Improper Neutralization of Input During Web Page Generation
Secondary CWECWE-116 — Improper Encoding or Escaping of Output
Attack vectorRemote, 0-click (zero user interaction post-delivery)
Privileges requiredNone
ScopeChanged — WebView context crosses trust boundary into native Android bridge

3.2 Vulnerable Component

File: assets/html/j/articleview-mobile.js Lines 95–99:

// article content was retrieved
loadCallback : function(content)
{
    // TODO : 3.0 : If file was missing, handle that correctly
    $(document.body).html(content);

Root cause: Externally-sourced HTML is passed directly to jQuery 3.4.1's .html() method with no sanitization. jQuery 3.4.1 executes embedded <script> tags and inline event handlers (onerror, onload). No call to DOMPurify, sanitize(), escapeHtml(), or equivalent exists anywhere in the 1,836-line file. The content variable originates from the Java layer without JS-side filtering.

The // TODO : 3.0 : If file was missing, handle that correctly comment immediately preceding the vulnerable call demonstrates the code was never production-hardened. This comment was present in every version of the app through the final release v8.33.0.0.

3.3 JavaScript Bridge Evidence

File: assets/html/j/articleview-mobile.js, lines 11–14:

// Android comm object
if (typeof PocketAndroidArticleInterface == 'undefined')
    PocketAndroidArticleInterface = false;

isAndroid = !!PocketAndroidArticleInterface;

Confirmed via DEX string analysis (classes2.dex):

PocketAndroidArticleInterface
setJavaScriptEnabled
addJavascriptInterface

Confirmed bridge methods from JS call sites: onReady(), onError(), onScrollChanged(), setFrozen(), placePageBlockers(), toggleFullscreen(), setViewType(), scrollToPosition(), onTextSearch(), onRequestedHighlightPatch(), updatePageSwipingDisabledAreas(), getHorizontalMargin(), getMaxMediaHeight(), isConnected().

3.4 Background Sync Service

AndroidManifest.xml confirms:

도구 다운로드