Skip to finding
important · Mobile

A permissionless Android app can steal Wikipedia session cookies and authenticated account data.

Affects

Wikipedia for Android, Wikimedia's encyclopedia client running on Android phones and tablets.

An ordinary Android app can target a device with an authenticated Wikipedia session without requesting a privileged permission.

Detail and 1 source

Intent redirection reaches an internal WebView whose cookie proxy exposes CentralAuth cookies and authenticated API responses.

Public proof-of-concept application code demonstrates cookie capture and authenticated API access.

The material held here does not identify the production releases containing the correction.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026