VORANT. Threat Intelligence Sign in Get the full feed

mObywatel iOS exposes user data via App Switcher

low vulnerability government-national

CVE-2025-11598 in mObywatel iOS app allowed unauthorized users to view personal information through the App Switcher after session logout, fixed in version 4.71.0.

CERT Polska coordinated the disclosure of CVE-2025-11598, a vulnerability in the mObywatel iOS application that allowed unauthorized access to personal information through the iOS App Switcher feature. The flaw enabled an attacker with physical access to view the account owner's personal data in the minimized app window even after the login session had ended, though reopening the app would require re-authentication. The specific data exposed depended on which screen was displayed before the application was minimized.

The vulnerability was responsibly reported by Maciej Krakowiak of DSecure.me and has been remediated in mObywatel version 4.71.0. This issue represents a privacy exposure risk rather than a remote exploitation vector, requiring physical access to an unlocked device to exploit. Users of the mObywatel iOS application should update to version 4.71.0 or later to address this vulnerability.

Mentioned in this report

Vulnerabilities CVE-2025-11598

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2025-11598

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free