securityonline.info 2 Oct 2026, 03:48 UTC

Critical Capacitor Flaw Lets Malicious Links Access App Data and Plugins

Critical Capacitor Flaw Lets Malicious Links Access App Data and Plugins
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability, CVE-2026-103922, has been identified in the Ionic Capacitor framework, which boasts over 5.5 million weekly downloads from npm. The flaw allows a malicious link to cause a script to run with the app’s origin by abusing Capacitor’s internal HTTP proxy path. If exploited, a remote attacker could access data via the app’s storage and cookies and potentially invoke any Capacitor plugin registered by the app, such as camera or file access. At the time of reporting, there was no public proof-of-concept, and there were no confirmed exploitation instances.

Affected versions include Capacitor 6.0.0 up to 6.2.2, 7.0.0 up to 7.6.9, and 8.0.0 up to 8.4.3, plus 8.5.0 up to 8.5.1, across Android, iOS, and Swift Package Manager builds. The attack works by bypassing a WebView navigation guard that checks only the host and scheme, leaving the path unchecked. A crafted link can direct a frame to Capacitor’s internal HTTP proxy, which fetches a URL chosen by the attacker and returns the response as if it originated from the app.

Disabling CapacitorHttp does not mitigate the issue, as the proxy path is served regardless. Patches are available in the respective branches (6.2.2, 7.6.9, 8.4.3, 8.5.1), and developers are urged to release updated app versions after upgrading, since the vulnerability remains in shipped apps rather than libraries alone.

View full article

Article by CyberSIXT