VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities

2026-09-25T20:52:03Z•7f2e0727776337f80f218c2bc8f70e55098ea5b485caf0951e1385d6d3b9b4ea
CVE-2026-18311CVE-2026-18312CVE-2026-75907CVE-2026-82356CVE-2026-82987CVE-2026-82988CVE-2026-82989CVE-2026-86867AndroidIoTOS-command-injectionRFIDSecure-Boot-bypassUEFIWebViewXSSaccess-controlarbitrary-APK-installationbroken-access-controlcertificate-impersonationcross-site-scriptingcryptographic-key-managementdevice-compromiseenterprise-securityhealthcareimproper-authenticationkey-rotationmulti-tenant-isolationroot-code-executionscreen-captureunauthenticated-access

What happened

CERT/CC advisories disclose multiple serious vulnerabilities: stored XSS in Readwise Reader for Android; unauthenticated screen exfiltration, arbitrary APK installation, and input injection in ViewSonic vCast; replayable RFID credentials in Norwegian Cruise Line door controllers; non-rotatable RSA keys in Imprivata EAM; cross-user conversation access in Kotaemon; Secure Boot bypass via vendor-signed UEFI Shell applications; and authenticated root-level OS command injection in Dokploy. Several issues enable unauthorized data access, persistence, arbitrary code execution, or physical access.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
7f2e0727776337f80f218c2bc8f70e55098ea5b485caf0951e1385d6d3b9b4ea
Enrichment time
2026-09-25T20:52:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.