The longest forever-day in consumer mobile history.

Section 1 conducts vulnerability research on products used by millions. Every finding is documented, verified, and published through coordinated disclosure.

CVE-2026-82090 — Pocket forever-day, 18 years, CVSS 9.2 Critical
Published CVE
Pocket (Mozilla)
CVE-2026-82090

Stored XSS via user-controlled HTML in WebView. All versions from v0 to v8.33.0.0. Thirteen years unpatched.

9.2 · Critical
Wallabag Android
CVE-2026-82089

Arbitrary HTML and JavaScript execution in WebView. No sanitization on archived content.

8.8 · High
Wallabag Web
CVE-2026-82081

HTML injection in article rendering. Stored persistently across user collections.

7.1 · High

The Pocket forever-day

A critical vulnerability present from the first version to the last, across every platform, for the entire life of the product.

First identified in 2012 on an iPhone 4. Formally reported in 2021. Rejected by Mozilla as out of scope in July 2024.

Published by MITRE as CVE-2026-82090 on August 28, 2026 — CVSS 4.0: 9.2 Critical. Every version of Pocket ever released, from v0 to v8.33.0.0, on every platform, carried the same stored XSS through the WebView JavaScript bridge.

Pocket was used by tens of millions of people across 18 years of product history. The vulnerability was never patched. The product was shut down with the flaw still present.

On the basis of publicly indexed records across CVE, NVD, CISA, and web archives, CVE-2026-82090 is the only critical forever-day (CVSS ≥ 9.0) documented on a standalone consumer mobile application.

Every other forever-day with CVSS ≥ 9.0 found on a mobile app is a companion for external hardware — a projector remote, a dashcam viewer, a garden robot controller — with product lifecycles of two to five years and user bases smaller by orders of magnitude.

Documented forever-days on mobile apps (CVSS ≥ 9.0)

CVE Product Type Lifecycle Severity
CVE-2026-82090 Pocket (Mozilla) Consumer app 18 years · tens of millions of users 9.2 Critical
CVE-2021-43717 Epson iProjection Projector companion ~4 years · niche Critical
CVE-2025-30137 G-Net GNET Dashcam companion ~3 years · minimal Critical
CVE-2026-10557 Yarbo Garden robot companion ~2 years · minimal Critical
Tencent Security Response Center Hall of Fame — ZampierZago, Top 100

Tencent Security Response Center

Top 100 in the Tencent SRC Hall of Fame. The only European independent researcher in the ranking — every other European entry operates with a team.

Vulnerability accepted on WeChat with credits published. Technical report covering six distinct code paths across WeChat Web, verified independently on five separate attack surfaces.

Verify on Tencent SRC →

Capabilities

Security research, audit, and coordinated disclosure as a service.

Attack surfaces

Android · iOS · Web applications · Desktop · WebView · REST API · AI agents and LLM integrations

Vulnerability classes

Stored and DOM-based XSS · JavaScript bridge escalation · CSRF chains · Prompt injection · Exported component misconfiguration · Command injection · Privacy and GDPR compliance

Stack

JavaScript (jQuery, AngularJS, React Native, Webpack) · Java and Kotlin · Objective-C · Python and Django · PHP · C/C++ native libraries · Smali/DEX reverse engineering

Deliverables

Technical report with reproducible evidence chain · Working PoC on controlled endpoints · Patch proposal · CVE advisory draft · GDPR compliance dossier

Engagement

One-shot security audit · Disclosure-in-progress consulting · Periodic retainer · On-call

Methodology

Static analysis on decompiled source. Dynamic verification on researcher-owned devices. Every finding timestamped with eIDAS-certified legal deposit before vendor contact. Full coordinated disclosure cycle through MITRE, CERT/CC, CISA, and vendor-specific platforms.