GHSL-2026-103: Local apps can hijack Wikipedia Android WebViews and steal session cookies - CVE-2026-65994
Published Oct 1, 2026
·Updated
A local application can invoke an exported Wikipedia Android activity to load an attacker-controlled webpage, steal session cookies, and expose personal information.
Affected Software
1 affected component
Wikimedia Foundation Wikipedia for Android
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs to have a local application on the Android device that can invoke the exported Wikipedia activity.
2
What information could be exposed if exploitation succeeds?
An attacker-controlled webpage loaded through the activity could steal session cookies and expose personal information.