Loading market data...
← Back to CVE feed

CVE-2026-82090

UNKNOWN View on NVD ↗

Description

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

Published: Aug 28, 2026 05:16 UTC Modified: Aug 28, 2026 20:20 UTC