Skip to finding
important · Mobile

One malicious deep-link click can leak a Wikipedia Android user's long-lived Wikimedia credentials to an attacker domain.

Affects

Wikipedia for Android, the Wikimedia reading application running on Android phones and tablets.

Suffix-only hostname and cookie checks accept a domain such as evil-wikipedia.org, load it in the app's WebView, and attach Wikimedia cookies.

Detail and 1 source

The attacker receives the username, long-lived token, and session token, which permit account takeover across Wikimedia projects.

The user must already be logged in and click the supplied wikipedia:// link.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026