CVE-2026-18312

CVE-2026-18312 published: Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL strings and inserts them into the DOM via innerHTML. Because t...

View full NVD advisory → ← Back to CVE watch