VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
Brief
Overview
Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.
- 2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization.
Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens.
Description
Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. It is available on multiple platforms including Android and can synchronize content across devices.
