CVE-2026-66832

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 21:17

Updated : 2026-09-01 21:16


NVD link : CVE-2026-66832

Mitre link : CVE-2026-66832

CVE.ORG link : CVE-2026-66832


JSON object : View

Products Affected

No product.

CWE
CWE-598

Use of HTTP Request With Sensitive Query String