Exposure of Confidential Information in mObywatel application
Vulnerability Description
In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require the user to log in). The data exposed depends on the last application view displayed before the application was minimized This issue was fixed in version 4.71.0
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11598
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Maciej Krakowiak [DSecure.me Sp. z o.o]
Affected Vendor
Centralny Ośrodek Informatyki
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.