← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 25, 2026 · 16:25via CERT/CC Vulnerability Notes

VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities

Brief

Overview

Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.

  • 2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization.

Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens.

Description

Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. It is available on multiple platforms including Android and can synchronize content across devices.

Read more on CERT/CC Vulnerability Notes→