
CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE published
Author: Ing. Zampier Zago (FUNFACTOR1) Division: Section 1 — Department of Cyber Security, PS 1978 Limited Contact: [email protected] Web: www.ps1978ltd.it Classification: Security Vulnerability Analysis — CVE-2026-82090
Dual-Use Content Disclaimer: This repository contains a vulnerability analysis and a Proof of Concept (PoC) for an End-of-Life (EOL) product. The information and code provided are strictly for educational purposes, defensive analysis, and official CVE documentation. The author holds no responsibility for any misuse of this information.
https://github.com/user-attachments/assets/e2b0aa46-df64-452b-afbf-fa31dd8c650d
A DOM-based Cross-Site Scripting (XSS) vulnerability has been confirmed in Pocket Android version 8.33.0.0 (package com.ideashower.readitlater.pro), the final release shipped by Mozilla / Read It Later, Inc. before service termination in July 2025. The vulnerability allows an attacker to inject and execute arbitrary JavaScript in the application's WebView without any user interaction beyond a single "Save to Pocket" action — a 0-click exploit post-delivery.
The root cause is the unsanitized injection of externally-sourced HTML content directly into the DOM via jQuery's .html() method ($(document.body).html(content)), in the asset-bundled file assets/html/j/articleview-mobile.js (lines 95–99). Content is fetched and rendered automatically in the background by com.pocket.sdk.offline.DownloadingService with no user interaction required.
The application also exposes a native Java-to-JavaScript bridge (PocketAndroidArticleInterface), registered via addJavascriptInterface and confirmed in classes2.dex, callable by JavaScript executing within the WebView.
Vendor disclosure record: The XSS was formally reported to Mozilla Security on 2024-07-10 with CWE-79 classification and full technical detail. Mozilla acknowledged receipt on 2024-07-11 and explicitly declined to remediate, declaring Pocket out of scope. Mozilla subsequently released v8.33.0.0 in 2025 with the vulnerable code entirely unchanged. Forensic analysis of v8.33.0.0 confirms the identical vulnerable call at lines 95–99 of articleview-mobile.js.
Lineage: The same identical line — $(document.body).html(content), in a file of the same name articleview-mobile.js — is present in the iOS counterpart bundle ReadItLaterPro.app (Pocket iOS v4.5.2), dating to the era immediately preceding the April 17, 2012 rebrand of Read It Later as Pocket. The CVE covers all versions from v0 through v8.33.0.0 — the defect has been continuously shipped, unmodified, across the product's entire 18-year lifespan (see §7). Forensic code-level confirmation via the oldest available bundle (iOS v4.5.2) dates the identical sink to at least 2012.
No patch is available. The product is abandoned. All installed instances remain permanently vulnerable.
| Field | Value |
|---|---|
| CVE | CVE-2026-82090 — Published 2026-08-28 — CNA: MITRE Corporation |
| Vulnerability type | DOM-Based XSS (0-click) + JavaScript Bridge Abuse |
| CWE | CWE-79, CWE-116 |
| Exploit status | 0-click, 0-day — no patch available; product End-of-Life |
| Vendor response | 2024-07-11 — "Pocket is out of scope" (Frida, Mozilla Security Team) |
| Affected product | Pocket Android v8.33.0.0 (final release) |
| Package ID | com.ideashower.readitlater.pro |
| Vendor | Mozilla Corporation / Read It Later, Inc. |
| CVSS v4.0 Score | 9.2 — CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Severity | CRITICAL |
| First reported to vendor | 2021-04-19 (paywall bypass) |
| XSS formally reported to Mozilla Security | 2024-07-10 |
| Final APK released with vulnerability intact | 2025 — v8.33.0.0 |
| Service sunset | 2025-07-08 |
| Code lineage | 18 years — all versions (v0 → v8.33.0.0, 2007 → 2025). Forensic code confirmation from 2012 iOS bundle. |
com.ideashower.readitlater.procom.ideashower.readitlater.pro_8.33.0.0.apkhttps://play.google.com/store/apps/details?id=com.ideashower.readitlater.pro but the app is no longer available for download.| Field | Value |
|---|---|
| Type | DOM-Based Cross-Site Scripting |
| CWE | CWE-79 — Improper Neutralization of Input During Web Page Generation |
| Secondary CWE | CWE-116 — Improper Encoding or Escaping of Output |
| Attack vector | Remote, 0-click (zero user interaction post-delivery) |
| Privileges required | None |
| Scope | Changed — WebView context crosses trust boundary into native Android bridge |
File: assets/html/j/articleview-mobile.js
Lines 95–99:
// article content was retrieved
loadCallback : function(content)
{
// TODO : 3.0 : If file was missing, handle that correctly
$(document.body).html(content);
Root cause: Externally-sourced HTML is passed directly to jQuery 3.4.1's .html() method with no sanitization. jQuery 3.4.1 executes embedded <script> tags and inline event handlers (onerror, onload). No call to DOMPurify, sanitize(), escapeHtml(), or equivalent exists anywhere in the 1,836-line file. The content variable originates from the Java layer without JS-side filtering.
The // TODO : 3.0 : If file was missing, handle that correctly comment immediately preceding the vulnerable call demonstrates the code was never production-hardened. This comment was present in every version of the app through the final release v8.33.0.0.
File: assets/html/j/articleview-mobile.js, lines 11–14:
// Android comm object
if (typeof PocketAndroidArticleInterface == 'undefined')
PocketAndroidArticleInterface = false;
isAndroid = !!PocketAndroidArticleInterface;
Confirmed via DEX string analysis (classes2.dex):
PocketAndroidArticleInterface
setJavaScriptEnabled
addJavascriptInterface
Confirmed bridge methods from JS call sites: onReady(), onError(), onScrollChanged(), setFrozen(), placePageBlockers(), toggleFullscreen(), setViewType(), scrollToPosition(), onTextSearch(), onRequestedHighlightPatch(), updatePageSwipingDisabledAreas(), getHorizontalMargin(), getMaxMediaHeight(), isConnected().
AndroidManifest.xml confirms: