ZOLL got ICSMA-26-041-01 for its ePCR iOS app, version 2.6.7, the tool EMS crews use for electronic patient-care reporting. CVE-2025-12699, unsanitized user input reflected into a WebView, base score 5.5. Script injection through PCR fields, exposing PHI and device telemetry captured in the back of an ambulance and rendered in a mobile web view that trusts what was typed into it.
Bryan Riggins reported it, and ZOLL runs a public advisory page that put the fix and the guidance in one place. A WebView is a browser. Anything you render in it is subject to the same injection rules as a website, and clinical form fields are user input like any other.