Critical Capacitor Flaw Lets Malicious Links Access App Data and Native Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A critical vulnerability in Capacitor for Android and iOS could let a malicious link opened inside an affected mobile app load attacker-controlled web content at the application’s trusted origin.

The issue, tracked as CVE-2026-103922, can expose app data stored in localStorage and cookies and give malicious scripts access to native Capacitor features available through registered plugins.

The vulnerability affects Capacitor applications using vulnerable releases of the Android, iOS, Maven, and Swift package distributions. It has received a critical CVSS score of 9.6 under CVSS v3.1, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N.

The flaw exists in Capacitor’s WebView navigation protection. The navigation guard checked the target URL’s scheme and host but did not validate the URL path. This allowed navigation requests to the internal /capacitor_http_interceptor path, which is hosted at the application’s own origin.

An attacker could craft a link that points to this internal endpoint while supplying an arbitrary remote URL. When a victim activates the link inside the application’s WebView, Capacitor’s native layer fetches the attacker-controlled remote content and returns it to the WebView.

Since the response is loaded under the legitimate application origin, scripts in the malicious page receive same-origin privileges.

Critical Capacitor Flaw

This creates a serious security boundary failure. The malicious code may read data from localStorage, access cookies, and interact with native capabilities exposed by Capacitor plugins.

The exact impact depends on the plugins the affected application registers. However, exposed functions could include access to device data, application features, authentication tokens, files, notifications, or other sensitive capabilities.

The issue is especially dangerous for Capacitor-based applications that display user-controlled links, including chat applications, comment sections, support portals, social feeds, rich-text documents, and in-app browsers. Exploitation requires user interaction, meaning a victim must open the malicious link from within the affected application.

According to the GitHub advisory, the internal proxy handler remained available even when the CapacitorHttp plugin was disabled, so disabling the plugin does not mitigate the issue on vulnerable versions.

Affected Capacitor versions include releases from 6.0.0 before 6.2.2, 7.0.0 before 7.6.9, 8.0.0 before 8.3.5, 8.3.5 before 8.4.3, and 8.5.0 before 8.5.1.

Developers should upgrade to the applicable patched release, rebuild their Android and iOS applications, and redistribute the updated versions to users.

The vendor’s fixes block frame navigations to the internal proxy path and ensure the proxy handler is served only when CapacitorHttp is enabled. The handler also no longer responds to document or main-frame requests, while legitimate fetch and XMLHttpRequest use remains unaffected.

Organizations unable to update immediately can implement a custom Capacitor plugin to reject navigation requests targeting /capacitor_http_interceptor. Developers should also sanitize and strictly validate all user-controlled URLs before rendering them inside an application WebView.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Critical Capacitor Flaw Lets Malicious Links Access App Data and Native Features appeared first on Cyber Security News.