Impact
The vulnerability stems from a flaw in the Wikipedia Android App that allows cross‑request disclosure of CentralAuth cookies. This flaw permits an attacker to read, intercept, or modify HTTP cookies that contain authentication tokens, exposing sensitive user session data. The weakness is a classic information‑leak scenario (CWE‑200).
Affected Systems
The impacted product is the Wikimedia Foundation’s Wikipedia Android App, version "main" following the latest code base changes. Specific version numbers are not listed, so all builds of the main branch that include the affected source code are considered vulnerable.
Risk and Exploitability
The CVSS score of 5.3 describes a moderate risk that could compromise user authentication information if exploited. EPSS data is not available, and the vulnerability is not in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is a network or local attacker who can observe HTTP traffic or trigger the app to send a request that leaks cookie data. However, the description does not confirm a publicly exploitable trigger, so the practical exploitation window may be limited to scenarios where the attacker can observe or influence inter‑app network traffic or interfere with the app’s request handling.
OpenCVE Enrichment