{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/capacitor-swift-pm--6.0.0--6.2.2--7.0.0--7.6.9--8.0.0--8.3.4--8.3.5--8.4.3--8.5.0--8.5.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-103922"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Capacitor Android (\u003e= 6.0.0, \u003c 6.2.2; \u003e= 7.0.0, \u003c 7.6.9; \u003e= 8.0.0, \u003c= 8.3.4; \u003e= 8.3.5, \u003c 8.4.3; \u003e= 8.5.0, \u003c 8.5.1)","Capacitor iOS (\u003e= 6.0.0, \u003c 6.2.2; \u003e= 7.0.0, \u003c 7.6.9; \u003e= 8.0.0, \u003c= 8.3.4; \u003e= 8.3.5, \u003c 8.4.3; \u003e= 8.5.0, \u003c 8.5.1)","capacitor-swift-pm (\u003e= 6.0.0, \u003c 6.2.2; \u003e= 7.0.0, \u003c 7.6.9; \u003e= 8.0.0, \u003c= 8.3.4; \u003e= 8.3.5, \u003c 8.4.3; \u003e= 8.5.0, \u003c 8.5.1)","com.capacitorjs:core (\u003e= 6.0.0, \u003c 6.2.2; \u003e= 7.0.0, \u003c 7.6.9; \u003e= 8.0.0, \u003c= 8.3.4; \u003e= 8.3.5, \u003c 8.4.3; \u003e= 8.5.0, \u003c 8.5.1)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","mobile","webview","cve-2026-103922"],"_cs_type":"advisory","_cs_vendors":["Ionic"],"content_html":"\u003cp\u003eIonic's Capacitor framework contains a critical vulnerability (CVE-2026-103922) affecting both Android and iOS platforms. The vulnerability stems from an insufficient validation process within the WebView navigation guard, which only checked the host and scheme of a URL, ignoring the path component. This allowed attackers to route navigation to the internal HTTP proxy path (\u003ccode\u003e/_capacitor_http_interceptor_\u003c/code\u003e), which is served by the application's origin regardless of the \u003ccode\u003eCapacitorHttp\u003c/code\u003e plugin status.\u003c/p\u003e\n\u003cp\u003eWhen an attacker forces the application to load this path as a document, the native layer fetches arbitrary content and injects it into the WebView as same-origin content. This grants the injected script access to \u003ccode\u003elocalStorage\u003c/code\u003e, cookies, and all exposed native Capacitor plugins. Any Capacitor-based application that renders user-supplied links or rich-text content is susceptible to this attack, which effectively elevates remote attacker control to the level of the application's internal trust.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a Capacitor-based application that renders user-controlled input (e.g., chat messages, comments).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious URL pointing to the application's internal proxy path (\u003ccode\u003e/_capacitor_http_interceptor_\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker injects this URL into the application via the identified input vector.\u003c/li\u003e\n\u003cli\u003eVictim clicks the link within the application's WebView.\u003c/li\u003e\n\u003cli\u003eThe Capacitor navigation guard evaluates the URL, observes the correct host and scheme, and permits the navigation.\u003c/li\u003e\n\u003cli\u003eThe native proxy handler intercepts the request for \u003ccode\u003e/_capacitor_http_interceptor_\u003c/code\u003e and fetches the attacker's malicious remote content.\u003c/li\u003e\n\u003cli\u003eThe WebView renders the malicious content within the app's origin, granting the attacker full access to local storage, cookies, and sensitive native plugins.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an attacker to execute arbitrary scripts with same-origin privileges. Successful exploitation results in the unauthorized exfiltration of sensitive data, such as session cookies and locally stored information. Furthermore, attackers can leverage the application's registered native plugins to perform unauthorized actions on the user's device, significantly impacting the integrity and confidentiality of any Capacitor-powered mobile application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Capacitor Android, iOS, and Core components to versions 6.2.2, 7.6.9, 8.4.3, or 8.5.1 to remediate CVE-2026-103922.\u003c/li\u003e\n\u003cli\u003eImplement an immediate block in the native navigation layer to cancel any navigation to paths starting with \u003ccode\u003e/_capacitor_http_interceptor_\u003c/code\u003e if an immediate upgrade is not possible.\u003c/li\u003e\n\u003cli\u003eAudit and sanitize all user-controlled link targets rendered within the WebView to prevent malicious navigation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:42:19Z","date_published":"2026-10-06T00:42:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-capacitor-webview-rce/","summary":"A flaw in the Capacitor WebView navigation guard allows attackers to force in-app navigation to an internal proxy path, enabling the execution of arbitrary remote content within the application's origin.","title":"Capacitor WebView Navigation Guard Bypass","url":"https://feed.craftedsignal.io/briefs/2026-10-capacitor-webview-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Capacitor-Swift-Pm (\u003e= 6.0.0, \u003c 6.2.2; \u003e= 7.0.0, \u003c 7.6.9; \u003e= 8.0.0, \u003c= 8.3.4; \u003e= 8.3.5, \u003c 8.4.3; \u003e= 8.5.0, \u003c 8.5.1)","version":"https://jsonfeed.org/version/1.1"}