MEDIUM 6.9 NVD

CVE-2026-66832

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string param

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.

References

Published: 2026-08-11 · Source: NVD · Feed updated: 2026-08-12
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-11 via NVD.
vulnfeed aggregates 9985 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.