CVE-2026-82090: Getpocket Pocket
Critical severity, CVSS 9.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods.
Affected products
- Getpocket Pocket: up to and including 8.33.0.0
Published 2026-08-28. Last modified 2026-09-09.