important · Mobile
One malicious deep-link click can leak a Wikipedia Android user's long-lived Wikimedia credentials to an attacker domain.
Affects
Wikipedia for Android, the Wikimedia reading application running on Android phones and tablets.
Suffix-only hostname and cookie checks accept a domain such as evil-wikipedia.org, load it in the app's WebView, and attach Wikimedia cookies.
Detail and 1 source
The attacker receives the username, long-lived token, and session token, which permit account takeover across Wikimedia projects.
The user must already be logged in and click the supplied wikipedia:// link.