<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-103922 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-103922/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:42:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-103922/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Capacitor WebView Navigation Guard Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-10-capacitor-webview-rce/</link><pubDate>Tue, 06 Oct 2026 00:42:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-capacitor-webview-rce/</guid><description>A flaw in the Capacitor WebView navigation guard allows attackers to force in-app navigation to an internal proxy path, enabling the execution of arbitrary remote content within the application's origin.</description><content:encoded><![CDATA[<p>Ionic's Capacitor framework contains a critical vulnerability (CVE-2026-103922) affecting both Android and iOS platforms. The vulnerability stems from an insufficient validation process within the WebView navigation guard, which only checked the host and scheme of a URL, ignoring the path component. This allowed attackers to route navigation to the internal HTTP proxy path (<code>/_capacitor_http_interceptor_</code>), which is served by the application's origin regardless of the <code>CapacitorHttp</code> plugin status.</p>
<p>When an attacker forces the application to load this path as a document, the native layer fetches arbitrary content and injects it into the WebView as same-origin content. This grants the injected script access to <code>localStorage</code>, cookies, and all exposed native Capacitor plugins. Any Capacitor-based application that renders user-supplied links or rich-text content is susceptible to this attack, which effectively elevates remote attacker control to the level of the application's internal trust.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a Capacitor-based application that renders user-controlled input (e.g., chat messages, comments).</li>
<li>Attacker crafts a malicious URL pointing to the application's internal proxy path (<code>/_capacitor_http_interceptor_</code>).</li>
<li>Attacker injects this URL into the application via the identified input vector.</li>
<li>Victim clicks the link within the application's WebView.</li>
<li>The Capacitor navigation guard evaluates the URL, observes the correct host and scheme, and permits the navigation.</li>
<li>The native proxy handler intercepts the request for <code>/_capacitor_http_interceptor_</code> and fetches the attacker's malicious remote content.</li>
<li>The WebView renders the malicious content within the app's origin, granting the attacker full access to local storage, cookies, and sensitive native plugins.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows an attacker to execute arbitrary scripts with same-origin privileges. Successful exploitation results in the unauthorized exfiltration of sensitive data, such as session cookies and locally stored information. Furthermore, attackers can leverage the application's registered native plugins to perform unauthorized actions on the user's device, significantly impacting the integrity and confidentiality of any Capacitor-powered mobile application.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for engineering and security teams:</p>
<ul>
<li>Upgrade Capacitor Android, iOS, and Core components to versions 6.2.2, 7.6.9, 8.4.3, or 8.5.1 to remediate CVE-2026-103922.</li>
<li>Implement an immediate block in the native navigation layer to cancel any navigation to paths starting with <code>/_capacitor_http_interceptor_</code> if an immediate upgrade is not possible.</li>
<li>Audit and sanitize all user-controlled link targets rendered within the WebView to prevent malicious navigation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>mobile</category><category>webview</category><category>cve-2026-103922</category></item></channel></rss>