important · Mobile / research
One Wikipedia Android deep link can disclose the victim's Wikimedia session after a tap.
Affects
Wikipedia for Android, the Wikimedia Foundation's encyclopedia application on Android devices.
The app accepts an attacker hostname ending in wikipedia.org and repeats the suffix mistake when deciding where to send CentralAuth cookies.
Detail and 1 source
Those cookies permit authenticated Wikimedia API access as the victim.
The maintainer tested a correction, but the advisory does not identify a fixed application version.