WORLDTECH NEWS Global technology intelligence.Contact
โ† Back to WORLDTECH

VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities

Network switches with status lights in a dark server rackAI illustration
WORLDTECH illustration ยท AI-generated (Canva)Google logo shown for identification only; no affiliation with or endorsement of WORLDTECH is implied.

What happened

Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. It is available on multiple platforms including Android and can synchronize content across devices.

An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Description Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. CVE-2026-18311 (the public catalogue number for a specific software flaw) : A stored cross-site scripting (XSS) vulnerability in the header rendering component in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via crafted document metadata fields.

Sources & evidence