What is CVE-2026-66832?
CVE-2026-66832 affects the Mira Android app, where in-app WebView redirects to third-party sites leak the user's live session token via URL query string and the persistent user identifier via the User-Agent header. This exposes sensitive session data to third-party web properties, requiring an urgent app update.
Azərbaycanca: CVE-2026-66832 boşluğu Mira Android tətbiqində aşkarlanıb. Tətbiq daxili WebView vasitəsilə üçüncü tərəf saytlarına keçid edərkən istifadəçinin canlı sessiya tokenini URL query string-də və daimi istifadəçi identifikatorunu User-Agent header-də göndərir. Bu, həssas məlumatların üçüncü tərəflərə ifşa olunmasına səbəb olur; təcili yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
What sensitive data does the Mira app WebView leak to third-party sites?
The live session token is leaked via URL query string, and the persistent user identifier is leaked via the User-Agent header.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.