A permissionless Android app can steal Wikipedia session cookies and authenticated account data.
Wikipedia for Android, Wikimedia's encyclopedia client running on Android phones and tablets.
An ordinary Android app can target a device with an authenticated Wikipedia session without requesting a privileged permission.
Detail and 1 source
Intent redirection reaches an internal WebView whose cookie proxy exposes CentralAuth cookies and authenticated API responses.
Public proof-of-concept application code demonstrates cookie capture and authenticated API access.
The material held here does not identify the production releases containing the correction.