ZOLL got ICSMA-26-041-01 for its ePCR iOS app, version 2.6.7, the tool EMS crews use for electronic patient-care reporting. CVE-2025-12699, unsanitized user input reflected into a WebView, base score 5.5. Script injection through PCR fields, exposing PHI and device telemetry captured in the back of an ambulance and rendered in a mobile web view that trusts what was typed into it.

Reflected injection of this kind occurs when an application takes text a person entered and renders it back inside a component that interprets markup and script. A native app hosting a web view is running an embedded browser, and if the field contents reach that view without being neutralized, characters that should be plain data are read as instructions instead. The boundary between content and code is the thing that failed.

Embedded web views are common in clinical mobile software because they let a team reuse existing web forms and layouts inside a native shell rather than build every screen twice. That convenience carries the web's entire injection problem into the app, and input captured under field conditions, often quickly and without review, is exactly the untrusted data that exposes it.

Bryan Riggins reported it, and ZOLL runs a public advisory page that put the fix and the guidance in one place. A WebView is a browser. Anything you render in it is subject to the same injection rules as a website, and clinical form fields are user input like any other.

A patient-care report drafted in the back of an ambulance holds identifiers, clinical detail and device readings, and a crew working an emergency has neither the time nor the tooling to notice that a form entry carried a payload. Content that executes inside the reporting app can reach the protected information the app handles and the telemetry the device records, all from an entry that looked like an ordinary note.