Skip to finding
important · Mobile / research

One Wikipedia Android deep link can disclose the victim's Wikimedia session after a tap.

Affects

Wikipedia for Android, the Wikimedia Foundation's encyclopedia application on Android devices.

The app accepts an attacker hostname ending in wikipedia.org and repeats the suffix mistake when deciding where to send CentralAuth cookies.

Detail and 1 source

Those cookies permit authenticated Wikimedia API access as the victim.

The maintainer tested a correction, but the advisory does not identify a fixed application version.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, October 4, 2026