Critical Capacitor Vulnerability (CVE-2026-103922) Exposes Mobile Apps to Remote Code Execution
A high-severity vulnerability (CVE-2026-103922, CVSS 9.3) in Capacitor, a cross-platform framework for building Android and iOS applications, allows attackers to execute malicious code within vulnerable apps under the guise of a trusted origin. The flaw stems from insufficient validation in Capacitor’s WebView navigation guard, which fails to properly verify URL paths, enabling exploitation of an internal proxy endpoint (/_capacitor_http_interceptor_).
How the Exploit Works
By tricking a user into clicking a malicious link within an app’s WebView, attackers can force the app to fetch attacker-controlled content via the proxy endpoint. The response is then rendered as a document under the app’s same-origin policy, granting malicious JavaScript access to:
- Same-origin data (cookies,
localStorage) - Native device functionality (via Capacitor plugins)
- Sensitive app operations (authentication tokens, API interactions)
The vulnerability affects apps regardless of whether the CapacitorHttp plugin is enabled, as the proxy endpoint remains accessible in vulnerable versions.
Affected Versions & Fixes
The flaw impacts:
- Capacitor 6.x (6.0.0–6.2.1)
- Capacitor 7.x (7.0.0–7.6.8)
- Capacitor 8.x (multiple pre-patch releases)
Patched versions are available:
- 6.2.2, 7.6.9, 8.3.5, 8.4.3, 8.5.1
The fix blocks navigation to the proxy endpoint and restricts its availability to when CapacitorHttp is explicitly enabled, while preserving legitimate subresource requests (e.g., fetch, XMLHttpRequest).
Mitigation & Impact
Developers must upgrade Capacitor, rebuild affected apps, and redistribute updates. Temporary workarounds include:
- Plugin overrides to block navigation to
/_capacitor_http_interceptor_ - Sanitizing user-controlled links in WebViews (e.g., chat messages, embedded content)
The vulnerability (tracked as CWE-346 and CWE-441) poses significant risks to apps handling sensitive data or native device features, with potential for data theft, unauthorized API access, or device compromise.
Source: https://gbhackers.com/capacitor-vulnerability/
Capacitor TPRM report: https://www.rankiteo.com/company/capacitor
"id": "cap1790944040",
"linkid": "capacitor",
"type": "Vulnerability",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Various (cross-industry)',
'location': 'Global',
'name': 'Apps using Capacitor 6.x (6.0.0–6.2.1)',
'type': 'Mobile application'},
{'industry': 'Various (cross-industry)',
'location': 'Global',
'name': 'Apps using Capacitor 7.x (7.0.0–7.6.8)',
'type': 'Mobile application'},
{'industry': 'Various (cross-industry)',
'location': 'Global',
'name': 'Apps using Capacitor 8.x (pre-patch releases)',
'type': 'Mobile application'}],
'attack_vector': 'Malicious link in WebView (phishing/social engineering)',
'data_breach': {'data_exfiltration': 'Possible (via malicious JavaScript '
'execution)',
'personally_identifiable_information': 'Possible (if stored '
'in same-origin data)',
'sensitivity_of_data': 'High (PII, authentication tokens, '
'native device access)',
'type_of_data_compromised': ['Same-origin data (cookies, '
'localStorage)',
'Authentication tokens',
'API interactions']},
'description': 'A high-severity vulnerability (CVE-2026-103922, CVSS 9.3) in '
'Capacitor, a cross-platform framework for building Android '
'and iOS applications, allows attackers to execute malicious '
'code within vulnerable apps under the guise of a trusted '
'origin. The flaw stems from insufficient validation in '
'Capacitor’s WebView navigation guard, which fails to properly '
'verify URL paths, enabling exploitation of an internal proxy '
'endpoint (`/_capacitor_http_interceptor_). By tricking a user '
'into clicking a malicious link within an app’s WebView, '
'attackers can force the app to fetch attacker-controlled '
'content via the proxy endpoint. The response is then rendered '
'as a document under the app’s same-origin policy, granting '
'malicious JavaScript access to same-origin data (cookies, '
'localStorage), native device functionality (via Capacitor '
'plugins), and sensitive app operations (authentication '
'tokens, API interactions).',
'impact': {'brand_reputation_impact': 'Potential loss of user trust in '
'affected apps',
'data_compromised': 'Same-origin data (cookies, localStorage), '
'authentication tokens, API interactions',
'identity_theft_risk': 'High (if PII or authentication tokens are '
'exposed)',
'operational_impact': 'Unauthorized access to native device '
'functionality, potential data theft, API '
'abuse',
'systems_affected': 'Mobile apps built with vulnerable Capacitor '
'versions (Android/iOS)'},
'initial_access_broker': {'entry_point': 'Malicious link in WebView'},
'post_incident_analysis': {'corrective_actions': 'Block navigation to proxy '
'endpoint; restrict endpoint '
'availability to when '
'CapacitorHttp is enabled',
'root_causes': 'Insufficient validation in '
'Capacitor’s WebView navigation '
'guard; accessible proxy endpoint '
'(`/_capacitor_http_interceptor_`)'},
'recommendations': ['Upgrade Capacitor to patched versions immediately',
'Sanitize user-controlled links in WebViews',
'Monitor for unauthorized API access or native device '
'functionality abuse',
'Educate users on phishing risks within app WebViews'],
'references': [{'source': 'CVE-2026-103922'},
{'source': 'CWE-346 (Origin Validation Error)'},
{'source': 'CWE-441 (Unintended Proxy or Intermediary)'}],
'response': {'containment_measures': 'Upgrade to patched Capacitor versions '
'(6.2.2, 7.6.9, 8.3.5, 8.4.3, 8.5.1)',
'remediation_measures': 'Rebuild and redistribute affected apps; '
'block navigation to '
'`/_capacitor_http_interceptor_` via '
'plugin overrides'},
'title': 'Critical Capacitor Vulnerability (CVE-2026-103922) Exposes Mobile '
'Apps to Remote Code Execution',
'type': 'Remote Code Execution (RCE)',
'vulnerability_exploited': 'CVE-2026-103922 (Capacitor WebView navigation '
'guard insufficient validation)'}