Command Palette
Search for a command to run...
Bundle Report
org-wikipedia vr/50590-r-2026-05-28
vr/50590-r-2026-05-28build 50590medium· 52
52b9e3d6042551fcde07ef3a70f99bc7ca9917b5e2a227c702534236df8654d6
- Platform
- Android · APK
- Bundle size
- 87.5 MB
- OS range
- Android API 23 → Android API 36
- Architectures
- arm64-v8a, armeabi-v7a, x86, x86_64
- Permissions
- 17
Store review readiness
Expected to pass review
All known pre-review checks pass.
Submit. All known pre-review checks pass. Reviewer may still raise non-static-analysis concerns (screenshots, metadata, UX) — those are out of scope here.
No pre-review rejection causes
No reviewer-flag items
What was checked and passed
- Data Safety form covers SDK-collected data categories
- Data Safety form covers third-party sharing
- No version-confirmed CVEs against bundled SDKs
- Static surface clusters with labeled-clean corpus neighbors· corpus k-NN bad-neighbor weight 0.00 (low)
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-27xj-rqx5-2255 — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-288c-cq4h-88gq — XML External Entity (XXE) Injection in Jackson Databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-3x8x-79m2-3w2w — jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-4gq5-ch57-c2mg — Arbitrary Code Execution in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-4w82-r329-3q67 — Deserialization of Untrusted Data in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-57j2-w4cx-62h2 — Deeply nested json in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-58pp-9c76-5625 — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-5949-rw7g-wx7w — Deserialization of untrusted data in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-5p34-5m6p-p58g — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-5r5r-6hpj-8gg9 — Serialization gadget exploit in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-5ww9-j83m-q7qx — Information exposure in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-645p-88qh-w398 — Arbitrary Code Execution in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-6fpp-rgj9-8rwc — Deserialization of untrusted data in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-6wqp-v4v6-c87c — Deserialization of Untrusted Data
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-758m-v56v-grj4 — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-85cw-hj65-qqv9 — Polymorphic Typing issue in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-89qr-369f-5m5x — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-8c4j-34r4-xr8g — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-8w26-6f25-cm9x — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-95cm-88f5-f2c7 — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-9gph-22xh-8x98 — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-9m6f-7xcq-8vf8 — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-9mxf-g3x6-wv74 — Server-Side Request Forgery (SSRF) in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-9vvp-fxw6-jcxr — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-c265-37vj-cwcc — Deserialization of untrusted data in Jackson Databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-c2q3-4qrh-fm48 — Deserialization of untrusted data in Jackson Databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-c8hm-7hpq-7jhg — com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted Data
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-cf6r-3wgc-h863 — Polymorphic deserialization of malicious object in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-cggj-fvv3-cqwv — FasterXML jackson-databind allows unauthenticated remote code execution
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-cjjf-94ff-43w7 — jackson-databind Deserialization of Untrusted Data vulnerability
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-cmfg-87vq-g5g4 — Deserialization of untrusted data in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-cvm9-fjm9-3572 — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-f3j5-rmmp-3fc5 — Improper Input Validation in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-f9hv-mg5h-xcw9 — Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-f9xh-2qgp-cq57 — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-fmmc-742q-jg75 — jackson-databind polymorphic typing issue
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-fqwf-pjwf-7vqv — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-gjmw-vf9h-g25v — jackson-databind polymorphic typing issue
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-gwp4-hfv6-p7hw — Deserialization of untrusted data in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-gww7-p5w4-wrfv — Deserialization of Untrusted Data in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-h3cw-g4mq-c5x2 — Code Injection in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-h4rc-386g-6m85 — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-h592-38cm-4ggp — jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-h822-r4r5-v8jg — Polymorphic Typing issue in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-j823-4qch-3rgm — Deserialization of untrusted data in Jackson Databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-jjjh-jjxp-wpff — Uncontrolled Resource Consumption in Jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-m6x4-97wx-4q27 — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-mc6h-4qgp-37qh — Deserialization of untrusted data in Jackson Databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-mph4-vhrx-mv67 — Deserialization of Untrusted Data in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-mx7p-6679-8g3q — Polymorphic Typing in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-mx9v-gmh4-mgqw — Deserialization of Untrusted Data in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-p43x-xfjf-5jhr — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-q93h-jc49-78gg — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-qjw2-hr98-qgfh — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-qmqc-x3r4-6v39 — Polymorphic deserialization of malicious object in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-qr7j-h6gg-jmgc — Deserialization of Untrusted Data in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-qxxx-2pp7-5hmx — jackson-databind is vulnerable to a deserialization flaw
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-r3gr-cxrf-hg25 — Serialization gadgets exploit in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-r695-7vr9-jgc2 — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-rf6r-2c4q-2vwg — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-rfx6-vp9g-rh7v — jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-rgv9-q543-rqg4 — Uncontrolled Resource Consumption in FasterXML jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-rpr3-cw39-3pxh — jackson-databind vulnerable to unsafe deserialization
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-v3xw-c963-f5hc — jackson-databind mishandles the interaction between serialization gadgets and typing
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-v585-23hc-c647 — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-vfqx-33qm-g869 — Unsafe Deserialization in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-w3f4-3q6j-rh82 — Deserialization of Untrusted Data in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-wh8g-3j2c-rqj5 — Serialization gadgets exploit in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info
GHSA-x2w5-5m2g-7h5m — XML External Entity Reference (XXE) in jackson-databind
component: jackson
- Historical CVE on SDK (build version not detected): GsonSDK vulnerability · info
GHSA-4jrv-ppp4-jm57 — Deserialization of Untrusted Data in Gson
component: gson
- Historical CVE on SDK (build version not detected): RetrofitSDK vulnerability · info
GHSA-8p8g-f9vg-r7xr — Directory Traversal vulnerability in Square Retrofit
component: retrofit
- Historical CVE on SDK (build version not detected): RetrofitSDK vulnerability · info
GHSA-j379-9jr9-w5cq — XML External Entity (XXE) vulnerability in Square Retrofit
component: retrofit
- Historical CVE on SDK (build version not detected): OkioSDK vulnerability · info
GHSA-w33c-445m-f8w7 — Okio Signed to Unsigned Conversion Error vulnerability
component: okio
- Exported Android componentExported component · info
org.wikipedia.search.SearchActivity (activity)
- Exported Android componentExported component · info
org.wikipedia.main.MainActivity (activity)
- Exported Android componentExported component · info
org.wikipedia.page.PageActivity (activity)
- Exported Android componentExported component · info
androidx.glance.appwidget.GlanceRemoteViewsService (service)
- Exported Android componentExported component · info
androidx.work.impl.background.systemjob.SystemJobService (service)
- Exported Android componentExported component · info
org.wikipedia.widgets.WidgetProviderFeaturedPage (receiver)
- Exported Android componentExported component · info
org.wikipedia.widgets.readingchallenge.ReadingChallengeWidgetReceiver (receiver)
- Exported Android componentExported component · info
androidx.profileinstaller.ProfileInstallReceiver (receiver)
- Exported Android componentExported component · info
org.wikipedia.widgets.WidgetProviderSearch (receiver)
- Exported Android componentExported component · info
org.wikipedia.notifications.NotificationPollBroadcastReceiver (receiver)
- Exported Android componentExported component · info
androidx.work.impl.diagnostics.DiagnosticsReceiver (receiver)
Want PR-level context for this app?
Connect the GitHub repo for this app to upgrade to L3. You'll get per-PR Check Runs, source-aware risk factors, and root-cause attribution against this exact bundle.