CVE-2026-65994: GHSL-2026-103: Local apps can hijack Wikipedia Android WebViews and steal session cookies - CVE-2026-65994
Published Oct 1, 2026
·Updated
A local application can invoke an exported Wikipedia Android activity to load an attacker-controlled webpage, steal session cookies, and expose personal information.
Affected Software
1 affected component
Wikimedia Foundation Wikipedia Android
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Users of the Wikipedia Android application are exposed if a malicious local application is present on the same Android device and can invoke the exported activity.
2
What does an attacker need to exploit it?
The attacker needs to install or otherwise run a local Android application on the target device, then use the exported Wikipedia activity to load an attacker-controlled webpage.
3
What information could be exposed if exploitation succeeds?
Successful exploitation can allow theft of session cookies and exposure of personal information.