Junglewise Threat Intelligence

CVE-2026-82090: Mozilla Pocket stored XSS in HTML injection

CVE-2026-82090 · Severity: info · CVSS 9.2 · Published 2026-08-28

Vendors: Mozilla.

Executive brief

Pocket is a browser extension and mobile app that saves web articles for later reading. A stored cross-site scripting (XSS) vulnerability allows attackers to inject malicious JavaScript that executes in the application, potentially stealing saved content, altering user preferences, or compromising user accounts. The flaw has existed across all versions since the application's inception and remains unpatched.

Technical details

The vulnerability is a stored XSS flaw in Pocket's "Save to Pocket" feature, where external HTML is injected directly into the DOM without proper sanitization. The root cause is insufficient input validation on HTML content being saved to the application. An attacker can craft a malicious page or article that, when saved to Pocket, injects JavaScript code. This code then executes with access to the native bridge methods, allowing modification of application state and access to user data. The vulnerability requires no special privileges—any user saving a malicious article can trigger it. No patch is currently available as of the advisory publication date.

Affected products

  • Mozilla Pocket through 8.33.0.0

Timeline

  • 2026-08-28: disclosed

References