| CVE ID | CVE-2025-11598 |
| Publication date | 03 February 2026 |
| Vendor | Centralny Ośrodek Informatyki |
| Product | mObywatel |
| Vulnerable versions | All before 4.71.0 (iOS only) |
| Vulnerability type (CWE) | Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in mObywatel application and participated in coordination of its disclosure.
The vulnerability CVE-2025-11598: In the mObywatel iOS application, an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require authentication). The data exposed depends on the last screen displayed before the application was minimized.
This issue was fixed in version 4.71.0
Credits
We thank Maciej Krakowiak (DSecure.me) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.