Capacitor CVE-2026-103922 Lets Malicious Links Reach App Data
CVE-2026-103922 lets malicious in-app links load remote content with a Capacitor app's trusted origin on Android and iOS.
A critical Capacitor flaw, CVE-2026-103922 and GitHub advisory GHSA-rvm3-566m-v7fv, can let a malicious link opened inside an affected Android or iOS app load attacker-controlled web content at the application's trusted origin. The WebView navigation guard validated scheme and host but not path, so requests can reach the internal /_capacitor_http_interceptor_ endpoint even when CapacitorHttp is disabled. Same-origin scripts may then read localStorage and cookies and call native features exposed by registered plugins. Sources disagree on the score: one reports CVSS 9.6 and the other CVSS 9.3. Vulnerable builds include 6.0.0 through 6.2.1, 7.0.0 through 7.6.8, and some 8.x releases; fixes are 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, and developers should upgrade, rebuild, and redistribute.
- CVE-2026-103922 (GitHub advisory GHSA-rvm3-566m-v7fv) is a critical Capacitor origin-validation flaw on Android and iOS that requires the victim to open a link.
- Sources disagree on severity: Cyber Security News scores it CVSS 9.6 and GBHackers scores it CVSS 9.3.
- The WebView navigation guard checked scheme and host but not path, allowing navigation to the internal /_capacitor_http_interceptor_ endpoint.
- Attacker-controlled content then runs at the app origin and can read localStorage and cookies and call native features exposed by registered plugins.
- Disabling CapacitorHttp does not mitigate the issue.
- Affected ranges are 6.0.0 through 6.2.1, 7.0.0 through 7.6.8, and some 8.x releases.
- Fixed versions are 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1; developers should upgrade, rebuild, and redistribute.
Coverage timelineoldest first · each row is one article
- · 6d agoCritical Capacitor Flaw Lets Malicious Links Access App Data and Native Features
Cyber Security News· 66
Critical Capacitor flaw CVE-2026-103922 lets malicious in-app links access app data and native features.
- · 6d agoCapacitor Vulnerability Lets Remote Content Run With Full App Origin Trust
GBHackers· 66
CVE-2026-103922 lets attacker-controlled content run with full origin trust inside Capacitor Android and iOS apps.
Vulnerabilities in this storyAll →
- CVE-2026-1039229.3<1%Capacitor WebView path bypass on Android and iOSpublished · Ionic Capacitor (Android and iOS) PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-103922 | Capacitor WebView path bypass on Android and iOS |