Capacitor: Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust

Capacitor: Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust

Critical Capacitor Vulnerability (CVE-2026-103922) Exposes Mobile Apps to Remote Code Execution

A high-severity vulnerability (CVE-2026-103922, CVSS 9.3) in Capacitor, a cross-platform framework for building Android and iOS applications, allows attackers to execute malicious code within vulnerable apps under the guise of a trusted origin. The flaw stems from insufficient validation in Capacitor’s WebView navigation guard, which fails to properly verify URL paths, enabling exploitation of an internal proxy endpoint (/_capacitor_http_interceptor_).

How the Exploit Works

By tricking a user into clicking a malicious link within an app’s WebView, attackers can force the app to fetch attacker-controlled content via the proxy endpoint. The response is then rendered as a document under the app’s same-origin policy, granting malicious JavaScript access to:

  • Same-origin data (cookies, localStorage)
  • Native device functionality (via Capacitor plugins)
  • Sensitive app operations (authentication tokens, API interactions)

The vulnerability affects apps regardless of whether the CapacitorHttp plugin is enabled, as the proxy endpoint remains accessible in vulnerable versions.

Affected Versions & Fixes

The flaw impacts:

  • Capacitor 6.x (6.0.0–6.2.1)
  • Capacitor 7.x (7.0.0–7.6.8)
  • Capacitor 8.x (multiple pre-patch releases)

Patched versions are available:

  • 6.2.2, 7.6.9, 8.3.5, 8.4.3, 8.5.1

The fix blocks navigation to the proxy endpoint and restricts its availability to when CapacitorHttp is explicitly enabled, while preserving legitimate subresource requests (e.g., fetch, XMLHttpRequest).

Mitigation & Impact

Developers must upgrade Capacitor, rebuild affected apps, and redistribute updates. Temporary workarounds include:

  • Plugin overrides to block navigation to /_capacitor_http_interceptor_
  • Sanitizing user-controlled links in WebViews (e.g., chat messages, embedded content)

The vulnerability (tracked as CWE-346 and CWE-441) poses significant risks to apps handling sensitive data or native device features, with potential for data theft, unauthorized API access, or device compromise.

Source: https://gbhackers.com/capacitor-vulnerability/

Capacitor TPRM report: https://www.rankiteo.com/company/capacitor

"id": "cap1790944040",
"linkid": "capacitor",
"type": "Vulnerability",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Various (cross-industry)',
                        'location': 'Global',
                        'name': 'Apps using Capacitor 6.x (6.0.0–6.2.1)',
                        'type': 'Mobile application'},
                       {'industry': 'Various (cross-industry)',
                        'location': 'Global',
                        'name': 'Apps using Capacitor 7.x (7.0.0–7.6.8)',
                        'type': 'Mobile application'},
                       {'industry': 'Various (cross-industry)',
                        'location': 'Global',
                        'name': 'Apps using Capacitor 8.x (pre-patch releases)',
                        'type': 'Mobile application'}],
 'attack_vector': 'Malicious link in WebView (phishing/social engineering)',
 'data_breach': {'data_exfiltration': 'Possible (via malicious JavaScript '
                                      'execution)',
                 'personally_identifiable_information': 'Possible (if stored '
                                                        'in same-origin data)',
                 'sensitivity_of_data': 'High (PII, authentication tokens, '
                                        'native device access)',
                 'type_of_data_compromised': ['Same-origin data (cookies, '
                                              'localStorage)',
                                              'Authentication tokens',
                                              'API interactions']},
 'description': 'A high-severity vulnerability (CVE-2026-103922, CVSS 9.3) in '
                'Capacitor, a cross-platform framework for building Android '
                'and iOS applications, allows attackers to execute malicious '
                'code within vulnerable apps under the guise of a trusted '
                'origin. The flaw stems from insufficient validation in '
                'Capacitor’s WebView navigation guard, which fails to properly '
                'verify URL paths, enabling exploitation of an internal proxy '
                'endpoint (`/_capacitor_http_interceptor_). By tricking a user '
                'into clicking a malicious link within an app’s WebView, '
                'attackers can force the app to fetch attacker-controlled '
                'content via the proxy endpoint. The response is then rendered '
                'as a document under the app’s same-origin policy, granting '
                'malicious JavaScript access to same-origin data (cookies, '
                'localStorage), native device functionality (via Capacitor '
                'plugins), and sensitive app operations (authentication '
                'tokens, API interactions).',
 'impact': {'brand_reputation_impact': 'Potential loss of user trust in '
                                       'affected apps',
            'data_compromised': 'Same-origin data (cookies, localStorage), '
                                'authentication tokens, API interactions',
            'identity_theft_risk': 'High (if PII or authentication tokens are '
                                   'exposed)',
            'operational_impact': 'Unauthorized access to native device '
                                  'functionality, potential data theft, API '
                                  'abuse',
            'systems_affected': 'Mobile apps built with vulnerable Capacitor '
                                'versions (Android/iOS)'},
 'initial_access_broker': {'entry_point': 'Malicious link in WebView'},
 'post_incident_analysis': {'corrective_actions': 'Block navigation to proxy '
                                                  'endpoint; restrict endpoint '
                                                  'availability to when '
                                                  'CapacitorHttp is enabled',
                            'root_causes': 'Insufficient validation in '
                                           'Capacitor’s WebView navigation '
                                           'guard; accessible proxy endpoint '
                                           '(`/_capacitor_http_interceptor_`)'},
 'recommendations': ['Upgrade Capacitor to patched versions immediately',
                     'Sanitize user-controlled links in WebViews',
                     'Monitor for unauthorized API access or native device '
                     'functionality abuse',
                     'Educate users on phishing risks within app WebViews'],
 'references': [{'source': 'CVE-2026-103922'},
                {'source': 'CWE-346 (Origin Validation Error)'},
                {'source': 'CWE-441 (Unintended Proxy or Intermediary)'}],
 'response': {'containment_measures': 'Upgrade to patched Capacitor versions '
                                      '(6.2.2, 7.6.9, 8.3.5, 8.4.3, 8.5.1)',
              'remediation_measures': 'Rebuild and redistribute affected apps; '
                                      'block navigation to '
                                      '`/_capacitor_http_interceptor_` via '
                                      'plugin overrides'},
 'title': 'Critical Capacitor Vulnerability (CVE-2026-103922) Exposes Mobile '
          'Apps to Remote Code Execution',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2026-103922 (Capacitor WebView navigation '
                            'guard insufficient validation)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.