External risk intelligence

Pocket External HTML Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-82090

The vulnerability involves client-side XSS within the 'Save to Pocket' functionality. This is a local browser or application-side issue that requires the user to interact with specific web content, rather than an internet-facing service, gateway, or network infrastructure component.

Cross-site Scripting

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Pocket, a tool used for saving web content, allows for the injection of external HTML which could alter application state. This could potentially lead to the execution of unauthorized JavaScript code, impacting user interactions with the application.

  • External code can alter application state.
  • Confirm relevance and exposure of this client-side risk.
  • Understand if saved content poses a risk.

Attack Path

How an attacker could exploit the issue

An attacker could inject malicious HTML into the "Save to Pocket" feature, allowing them to execute JavaScript code. This could lead to altering the application's state through native bridge methods.

  • Entry condition: No authentication or network access required.
  • Trigger point: User interaction with "Save to Pocket".
  • Resulting risk: Malicious JavaScript execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a malicious website to inject external HTML into the Pocket application's DOM, potentially altering application state when supported by the advisory.

  • User interface and application state may be affected.
  • Injection occurs via external HTML in Pocket.
  • Application state could be altered.

Operational Fix

Recommended remediation, mitigation, and detection steps

The "Save to Pocket" functionality in the affected application presents a cross-site scripting (XSS) vulnerability that can allow JavaScript to alter application state via native bridge methods. Owners of the application and the underlying platform infrastructure are likely responsible for addressing this issue. The first practical step is to identify all instances of the affected application, assess their exposure and criticality, and then coordinate remediation efforts.

  • Application owners should manage the fix.
  • Verify user interaction and reachability.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Pocket?

Pocket is an application designed to help users save articles, videos, and web pages for later viewing. It functions as a digital bookmarking tool that stores content from across the internet, allowing users to aggregate and read material offline or in a simplified format within the application interface.

What does CVE-2026-82090 mean?

This CVE identifies a Cross-Site Scripting (XSS) vulnerability. It occurs when the software incorrectly handles external HTML during the 'Save to Pocket' process, injecting it into the application's Document Object Model (DOM). This allows unauthorized JavaScript to run and potentially manipulate the application's internal state using native bridge commands.

How is this vulnerability triggered?

The trigger involves the 'Save to Pocket' feature processing malicious external HTML. This issue does not stem from general background network activity or static application usage; it specifically requires the application to attempt to save or render specially crafted content that injects scripts into the interface.

Is this vulnerability an internet-facing risk?

According to Halo Surface Signal, this is very unlikely to be an internet-facing infrastructure risk. It is primarily a client-side issue residing within the user's browser or the Pocket application itself. It depends on user interaction with specific, malicious web content rather than exploiting a publicly accessible server or network gateway.

Do I need to take action to address CVE-2026-82090?

Yes. Start by identifying where the affected versions of the Pocket software are installed across your environment. Once you have a list of these instances, assess their importance to your workflow and coordinate with the appropriate teams to track and apply official security updates as they become available to patch the DOM injection flaw.

References