Critical Capacitor Flaw Exposes App Data and Native Features via Malicious Links
A critical vulnerability (CVE-2026-103922) in Capacitor for Android and iOS allows malicious links to load attacker-controlled content at the app's trusted origin, enabling access to sensitive data and native features.

A critical vulnerability, tracked as CVE-2026-103922, has been discovered in Capacitor for Android and iOS, posing a significant risk to mobile applications. This flaw allows malicious links, when opened within an affected application, to load attacker-controlled web content under the guise of the application's trusted origin. This boundary failure enables malicious scripts to access sensitive app data, such as information stored in localStorage and cookies, and to interact with native Capacitor features exposed through registered plugins.
The vulnerability stems from an issue in Capacitor's WebView navigation protection. While the navigation guard checked the target URL's scheme and host, it failed to validate the URL path. This oversight permitted navigation requests to an internal path, /capacitor_http_interceptor, which is hosted at the application's own origin. An attacker could craft a malicious link pointing to this internal endpoint while specifying an arbitrary remote URL. When a user clicks this link within the application's WebView, Capacitor's native layer fetches the attacker-controlled remote content and serves it back to the WebView. Because this content is loaded under the legitimate application origin, any scripts within the malicious page gain same-origin privileges, effectively bypassing security controls.
The potential impact of this vulnerability is severe, depending on the specific plugins registered by the affected application. Malicious code could potentially read sensitive data from localStorage, access cookies, and leverage native capabilities such as device information, authentication tokens, file system access, notification systems, and other critical functions. The risk is particularly elevated for applications that display user-generated content or links, including chat applications, comment sections, support portals, social feeds, rich-text editors, and in-app browsers.
Exploitation of this vulnerability requires direct user interaction, meaning a victim must click the malicious link from within the vulnerable application. Notably, the GitHub advisory indicates that the internal proxy handler remained accessible even when the CapacitorHttp plugin was disabled, meaning disabling this plugin does not serve as a mitigation on affected versions. The vulnerability has been assigned a critical CVSS score of 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Several versions of Capacitor are affected by this flaw. Specifically, releases from 6.0.0 before 6.2.2, 7.0.0 before 7.6.9, 8.0.0 before 8.3.5, 8.3.5 before 8.4.3, and 8.5.0 before 8.5.1 are vulnerable. Developers are strongly advised to upgrade to the applicable patched release, rebuild their Android and iOS applications, and redistribute the updated versions to their users to mitigate the risk.
The vendor has implemented fixes that block frame navigations to the internal proxy path and ensure the proxy handler is only served when CapacitorHttp is enabled. Furthermore, the handler no longer responds to document or main-frame requests, while legitimate fetch and XMLHttpRequest operations remain unaffected. For organizations unable to update immediately, a temporary workaround involves implementing a custom Capacitor plugin to reject navigation requests targeting /capacitor_http_interceptor. Additionally, developers should prioritize sanitizing and strictly validating all user-controlled URLs before rendering them within an application's WebView.
This vulnerability highlights the ongoing challenges in securing the complex web of dependencies and integrations within modern mobile application development frameworks. As applications become more feature-rich and rely on external content, the potential attack surface expands, necessitating continuous vigilance and prompt patching of underlying components.