CVE-2026-82090EPSS p35.7%
CVE-2026-82090CVE-2026-82090
Description
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods.
Scoring
| EPSS | 0.44% probability of exploitation · percentile 35.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-09 |