Cyber Security News

Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust

A critical vulnerability in Capacitor, identified as CVE-2026-103922, could allow attacker-controlled remote content to execute within vulnerable Android and iOS applications, posing as the application’s own trusted origin.

This flaw, assigned a CVSS score of 9.3, affects WebView navigation handling in Capacitor and can expose same-origin data, cookies, local storage, and native functionality available through registered Capacitor plugins.

Capacitor Vulnerability

The issue, detailed in GitHub Security Advisory GHSA-rvm3-566m-v7fv, arises from incomplete validation in Capacitor’s WebView navigation guard. The affected logic verified a target URL’s scheme and host but failed to validate its path.

This oversight enabled navigation to Capacitor’s internal /_capacitor_http_interceptor_ endpoint, which is hosted at the application’s origin and treated as a legitimate in-app destination.

When an attacker convinces a victim to click on a malicious link within an application’s WebView, this internal proxy endpoint can be exploited to fetch a remote URL chosen by the attacker.

Crucially, the fetched response is returned to the WebView as a document under the affected application’s trusted origin, rather than the attacker’s remote origin. As a result, any JavaScript embedded in that response can inherit full same-origin privileges within the Capacitor application.

This means that malicious code could potentially access localStorage, cookies, and any privileged native capabilities provided through configured Capacitor plugins. The impact depends on the app’s plugin configuration and stored data.

Affected applications that manage authentication tokens, sensitive user data, device features, or backend API interactions face significant risk. The weakness maps to CWE-346, which refers to an origin-validation error, and CWE-441, which indicates an unintended proxy or “confused deputy” condition.

The vulnerability impacts both `@capacitor/android` and `@capacitor/ios`, as well as the Maven `com.capacitorjs:core` package and the Swift Package Manager distribution.

Vulnerable versions include Capacitor releases from 6.0.0 to 6.2.1, 7.0.0 to 7.6.8, and several 8.x releases before the fixed versions. The fixed versions are 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1.

Disabling the CapacitorHttp plugin does not protect vulnerable applications. In affected versions, the internal proxy handler is accessible even if the plugin has not been enabled, expanding the exposure to apps that do not intentionally use the Capacitor HTTP proxy functionality.

The maintainers have addressed the issue by blocking frame navigations to the internal proxy path and ensuring that the proxy handler is available only when CapacitorHttp is enabled.

The patched implementation also prevents the proxy endpoint from serving main-document requests while preserving legitimate fetch and XMLHttpRequest behavior, as these operate as subresource requests.

Developers should upgrade to a patched version of Capacitor, rebuild the affected Android and iOS applications, and promptly redistribute the updated versions.

Organizations unable to patch immediately can implement an Android or iOS plugin override to cancel navigation attempts starting with /_capacitor_http_interceptor_. Also sanitize and restrict user-controlled links rendered in WebViews, especially in applications that support chat messages, comments, embedded rich text, or external content.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago