Cyber Security News

Critical Capacitor Flaw Lets Malicious Links Access App Data and Native Features

A critical vulnerability in Capacitor for Android and iOS could let a malicious link opened inside an affected mobile app load attacker-controlled web content at the application’s trusted origin.

The issue, tracked as CVE-2026-103922, can expose app data stored in localStorage and cookies and give malicious scripts access to native Capacitor features available through registered plugins.

The vulnerability affects Capacitor applications using vulnerable releases of the Android, iOS, Maven, and Swift package distributions. It has received a critical CVSS score of 9.6 under CVSS v3.1, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N.

The flaw exists in Capacitor’s WebView navigation protection. The navigation guard checked the target URL’s scheme and host but did not validate the URL path. This allowed navigation requests to the internal /capacitor_http_interceptor path, which is hosted at the application’s own origin.

An attacker could craft a link that points to this internal endpoint while supplying an arbitrary remote URL. When a victim activates the link inside the application’s WebView, Capacitor’s native layer fetches the attacker-controlled remote content and returns it to the WebView.

Since the response is loaded under the legitimate application origin, scripts in the malicious page receive same-origin privileges.

Critical Capacitor Flaw

This creates a serious security boundary failure. The malicious code may read data from localStorage, access cookies, and interact with native capabilities exposed by Capacitor plugins.

The exact impact depends on the plugins the affected application registers. However, exposed functions could include access to device data, application features, authentication tokens, files, notifications, or other sensitive capabilities.

The issue is especially dangerous for Capacitor-based applications that display user-controlled links, including chat applications, comment sections, support portals, social feeds, rich-text documents, and in-app browsers. Exploitation requires user interaction, meaning a victim must open the malicious link from within the affected application.

According to the GitHub advisory, the internal proxy handler remained available even when the CapacitorHttp plugin was disabled, so disabling the plugin does not mitigate the issue on vulnerable versions.

Affected Capacitor versions include releases from 6.0.0 before 6.2.2, 7.0.0 before 7.6.9, 8.0.0 before 8.3.5, 8.3.5 before 8.4.3, and 8.5.0 before 8.5.1.

Developers should upgrade to the applicable patched release, rebuild their Android and iOS applications, and redistribute the updated versions to users.

The vendor’s fixes block frame navigations to the internal proxy path and ensure the proxy handler is served only when CapacitorHttp is enabled. The handler also no longer responds to document or main-frame requests, while legitimate fetch and XMLHttpRequest use remains unaffected.

Organizations unable to update immediately can implement a custom Capacitor plugin to reject navigation requests targeting /capacitor_http_interceptor. Developers should also sanitize and strictly validate all user-controlled URLs before rendering them inside an application WebView.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks

Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…

1 hour ago

Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network

A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…

1 hour ago

GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…

1 hour ago

From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring

Every function in a security operations center, from alert triage to incident response, depends on…

1 hour ago

ASOS Hacked – App Users Receive Notifications Sent by Hackers

ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…

2 hours ago

Aembit Extends Access Controls to Personal AI Agents

Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…

2 hours ago