Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust
CVE-2026-103922 lets attacker-controlled content run with full origin trust inside Capacitor Android and iOS apps.
A critical Capacitor flaw, CVE-2026-103922, is scored CVSS 9.3 and tracked as GitHub advisory GHSA-rvm3-566m-v7fv. The WebView navigation guard checked a URL’s scheme and host but not its path, allowing navigation to the internal /_capacitor_http_interceptor_ endpoint so attacker-chosen remote content is returned as the application’s own origin. JavaScript in that response could access localStorage, cookies, and native capabilities exposed through Capacitor plugins. Vulnerable versions include 6.0.0 through 6.2.1, 7.0.0 through 7.6.8, and some 8.x releases; fixed versions are 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1. Disabling the CapacitorHttp plugin does not protect affected apps.