Critical Capacitor Flaw Lets Malicious Links Access App Data and Native Features
Critical Capacitor flaw CVE-2026-103922 lets malicious in-app links access app data and native features.
A critical Capacitor flaw, CVE-2026-103922, can let a malicious link opened inside an affected Android or iOS app load attacker-controlled web content at the application's trusted origin. The WebView navigation guard validated scheme and host but not path, allowing requests to the internal capacitor HTTP interceptor even when CapacitorHttp was disabled. Same-origin scripts may then read localStorage and cookies and call native features exposed by registered plugins. It scores CVSS 9.6 and affects releases from 6.0.0 before 6.2.2, 7.0.0 before 7.6.9, and several 8.x builds; developers should upgrade, rebuild, and redistribute.
- CVE-2026-103922 scores CVSS 9.6 and requires the victim to open a link.
- The WebView guard checked scheme and host but not the URL path.
- Malicious content loads at the app origin and can reach storage, cookies, and plugins.
- Capacitor 6, 7, and 8 are affected; disabling CapacitorHttp does not mitigate it.
Vulnerabilities mentionedAll →
- CVE-2026-1039229.3<1%Capacitor WebView path bypass on Android and iOSpublished · Ionic Capacitor (Android and iOS) PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-103922 | Capacitor WebView path bypass on Android and iOS |
Full article498 words · extracted from cybersecuritynews.com · click to collapse
A critical vulnerability in Capacitor for Android and iOS could let a malicious link opened inside an affected mobile app load attacker-controlled web content at the application’s trusted origin.
The issue, tracked as CVE-2026-103922, can expose app data stored in localStorage and cookies and give malicious scripts access to native Capacitor features available through registered plugins.
The vulnerability affects Capacitor applications using vulnerable releases of the Android, iOS, Maven, and Swift package distributions. It has received a critical CVSS score of 9.6 under CVSS v3.1, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N.
The flaw exists in Capacitor’s WebView navigation protection. The navigation guard checked the target URL’s scheme and host but did not validate the URL path. This allowed navigation requests to the internal /capacitor_http_interceptor path, which is hosted at the application’s own origin.
An attacker could craft a link that points to this internal endpoint while supplying an arbitrary remote URL. When a victim activates the link inside the application’s WebView, Capacitor’s native layer fetches the attacker-controlled remote content and returns it to the WebView.
Since the response is loaded under the legitimate application origin, scripts in the malicious page receive same-origin privileges.
Critical Capacitor Flaw
This creates a serious security boundary failure. The malicious code may read data from localStorage, access cookies, and interact with native capabilities exposed by Capacitor plugins.
The exact impact depends on the plugins the affected application registers. However, exposed functions could include access to device data, application features, authentication tokens, files, notifications, or other sensitive capabilities.
The issue is especially dangerous for Capacitor-based applications that display user-controlled links, including chat applications, comment sections, support portals, social feeds, rich-text documents, and in-app browsers. Exploitation requires user interaction, meaning a victim must open the malicious link from within the affected application.
According to the GitHub advisory, the internal proxy handler remained available even when the CapacitorHttp plugin was disabled, so disabling the plugin does not mitigate the issue on vulnerable versions.
Affected Capacitor versions include releases from 6.0.0 before 6.2.2, 7.0.0 before 7.6.9, 8.0.0 before 8.3.5, 8.3.5 before 8.4.3, and 8.5.0 before 8.5.1.
Developers should upgrade to the applicable patched release, rebuild their Android and iOS applications, and redistribute the updated versions to users.
The vendor’s fixes block frame navigations to the internal proxy path and ensure the proxy handler is served only when CapacitorHttp is enabled. The handler also no longer responds to document or main-frame requests, while legitimate fetch and XMLHttpRequest use remains unaffected.
Organizations unable to update immediately can implement a custom Capacitor plugin to reject navigation requests targeting /capacitor_http_interceptor. Developers should also sanitize and strictly validate all user-controlled URLs before rendering them inside an application WebView.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.