CVE-2026-100379: Cross-request disclosure of CentralAuth cookies in Wikipedia Android App
Published Sep 25, 2026
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies.
This issue affects Wikipedia Android App: main.
Affected Software
1 affected component
Wikimedia Foundation Wikipedia Android App
Event History
Sep 25, 2026
CVE Published
via MITRE·08:54 PM
Data Sourced
via MITRE·08:54 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which code line should teams review for this issue?
The affected line is identified as the Wikipedia Android App main branch. The provided data does not specify affected released versions or a fixed version.
2
Where can teams track the investigation and implementation details?
The issue is referenced at https://phabricator.wikimedia.org/T433832 and the associated code change at https://github.com/wikimedia/apps-android-wikipedia/pull/6768.