Capacitor WebView Flaw Let Malicious Links Load Remote Content at App Origin (CVE-2026-103922, CVSS 9.3)
A critical advisory (GHSA-rvm3-566m-v7fv) disclosed on 2026-10-05 reports a same-origin bypass affecting both the Android and iOS builds of Capacitor, tracked as CVE-2026-103922 (CVSS 9.3, public PoC).
What was reported
Per the advisory, Capacitor's WebView navigation guard validated only the host and scheme of a target URL, not its path. Capacitor serves an internal HTTP proxy path (/_capacitor_http_interceptor_) at the app's own origin, so a frame navigation to that path was always treated as legitimate in-app navigation. Loading it as a document caused the native layer to fetch an attacker-specified arbitrary URL and return the response at the app's own origin — meaning any script in that response ran with full same-origin trust: access to localStorage, cookies, and every native capability exposed through the app's registered Capacitor plugins. The advisory notes the proxy handler was served regardless of whether the CapacitorHttp plugin was enabled, so apps that never enabled it were still affected.
Why it matters
Exploitation only requires a victim to tap a link inside the app's WebView, so any Capacitor app that renders user-controlled or unsanitized links — chat messages, comments, rich-text content — is a viable delivery surface. Given the breadth of Capacitor's use in cross-platform mobile apps and the ability to pivot from a single link tap to full same-origin script execution and native plugin access, this is a serious client-side compromise primitive for both Android and iOS releases.
What defenders should do now
- Identify any Capacitor-based apps in your environment or portfolio (check
@capacitor/android,@capacitor/ios,capacitor-swift-pm, orcom.capacitorjs:coredependency manifests) and prioritize upgrading to the patched versions, then rebuild and redistribute. - If immediate upgrade isn't possible, per the advisory's workaround: disabling
CapacitorHttpalone is not sufficient. Implement a plugin override (shouldOverrideLoadon both Android and iOS) that cancels navigation when the target path starts with/_capacitor_http_interceptor_, while allowing all other navigation through unchanged. - Independently of patching, sanitize any user-controlled link targets before rendering them inside app WebViews, since link-tap is the exploitation trigger.
- For hunting, review mobile app crash/network telemetry and WebView navigation logs (where available) for unexpected requests to the internal proxy path, and audit third-party content sources (chat, comments, deep links) feeding into Capacitor WebViews.
This is developing, net-new intel based on a vendor advisory published today; details may be refined as more analysis emerges. See the original GitHub Security Advisory for full technical detail and patch versions: GHSA-rvm3-566m-v7fv.