Critical Capacitor Fls-1.0.0 Flaw Exposes App Data, Native Features
Key Takeaways A critical vulnerability, CVE-2026-103922, has been discovered in Capacitor for Android and iOS. The flaw allows attackers to load malicious web content within an affected...
Key Takeaways
- A critical vulnerability, CVE-2026-103922, has been discovered in Capacitor for Android and iOS.
- The flaw allows attackers to load malicious web content within an affected application’s trusted origin, potentially exposing sensitive app data and native features.
- The vulnerability impacts Capacitor applications utilizing specific Android, iOS, Maven, and Swift package distributions across multiple version branches.
- Rated with a critical CVSS v3.1 score of 9.6, a fix is available in updated Capacitor releases.
Critical Capacitor Flaw Exposes App Data and Native Features
A severe security vulnerability in Capacitor for Android and iOS could enable attackers to execute arbitrary web content from within a mobile application’s trusted origin. This critical flaw, identified as CVE-2026-103922, poses a significant risk to user data and device integrity.
Table Of Content
The vulnerability’s exploitation could lead to the exposure of sensitive application data, including information stored in localStorage and cookies. Furthermore, malicious scripts could gain unauthorized access to native Capacitor features made available through registered plugins, depending on the application’s configuration.
Scope and Severity
Applications built with Capacitor are affected if they incorporate vulnerable releases of the Android, iOS, Maven, or Swift package distributions. The vulnerability has been assigned a critical CVSS v3.1 score of 9.6, with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N, underscoring its potential for widespread and serious impact.
The root cause of the flaw lies within Capacitor’s WebView navigation protection mechanism. While designed to prevent unauthorized navigation, the system incorrectly validated target URLs. Specifically, it checked the scheme and host but failed to properly scrutinize the URL path. This oversight permitted navigation requests to an internal /capacitor_http_interceptor path, which is hosted on the application’s own origin.
An attacker could exploit this by crafting a malicious link that directs to this internal endpoint while simultaneously supplying a remote, attacker-controlled URL. Should a user open this link within the application’s WebView, Capacitor’s native layer would fetch the remote, malicious content and deliver it back to the WebView. Crucially, because this response is loaded under the application’s legitimate origin, any scripts embedded in the malicious page would inherit same-origin privileges, effectively bypassing security boundaries.
Potential Impact and Affected Versions
This security boundary failure allows malicious code to perform actions such as reading data from localStorage, accessing cookies, and interacting with native capabilities exposed via Capacitor plugins. The precise extent of the impact is contingent on the specific plugins an affected application has registered, but could include unauthorized access to device data, application features, authentication tokens, files, notifications, or other sensitive functionalities.
The vulnerability is particularly dangerous for Capacitor-based applications that render user-controlled links. This includes, but is not limited to, chat applications, comment sections, support portals, social feeds, rich-text document viewers, and in-app browsers. Successful exploitation requires user interaction, meaning a victim must click on the malicious link from within the compromised application.
According to the GitHub advisory, the internal proxy handler remained active even when the CapacitorHttp plugin was disabled. This means that merely disabling the plugin does not mitigate the vulnerability in affected versions.
Affected Capacitor versions include releases from 6.0.0 before 6.2.2, 7.0.0 before 7.6.9, 8.0.0 before 8.3.5, 8.3.5 before 8.4.3, and 8.5.0 before 8.5.1.
What You Should Do
- Upgrade Immediately: Developers must upgrade their Capacitor projects to the applicable patched releases. This involves updating to Capacitor versions 6.2.2 or later, 7.6.9 or later, 8.3.5 or later (if coming from 8.3.5, then 8.4.3 or later), or 8.5.1 or later.
- Rebuild and Redistribute: After upgrading, rebuild both Android and iOS applications and promptly redistribute the updated versions to end-users.
- Implement Custom Plugin (Temporary Mitigation): For organizations unable to update immediately, a temporary mitigation involves implementing a custom Capacitor plugin designed to reject navigation requests specifically targeting
/capacitor_http_interceptor. - Strict URL Validation: Developers should rigorously sanitize and validate all user-controlled URLs before they are rendered within an application WebView to prevent similar vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.