CVE-2026-103922: Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path
### Impact Capacitor's WebView navigation guard validated only the **host and scheme** of a target URL, not its **path**. Because the internal HTTP proxy path (`/_capacitor_http_interceptor_`) is served at the application's own origin, a frame navigation to it was always treated as in-app navigation and allowed. Loading that path as a document caused the native layer to fetch an arbitrary, caller-specified URL and return the response body to the WebView **at the app's own origin**. Script in that response then ran with full same-origin trust: access to `localStorage`, cookies, and every native capability the application exposes through its registered Capacitor plugins. The proxy handler was additionally served **regardless of whether the `CapacitorHttp` plugin was enabled**, so applications that never enabled `CapacitorHttp` were also affected. Exploitation requires a victim to activate a link inside the application's WebView. Any Capacitor application that renders user-controlled or unsanitized links (chat messages, comments, rich-text content) is a viable delivery surface. Both **Android and iOS** are affected. ### Patches Two changes on each platform: 1. The navigation guard now blocks frame navigations whose path is the internal proxy path. 2. The proxy handler is served only when `CapacitorHttp` is enabled, and never for a document (main frame) request. Legitimate `CapacitorHttp` usage is unaffected. `fetch` and `XMLHttpRequest` are subresource requests and do not pass through the navigation guard. Upgrade to a patched version, then rebuild and redistribute your application. ### Workarounds If you cannot upgrade immediately, note first that **disabling `CapacitorHttp` is not sufficient** on affected versions, because the proxy path is served regardless of that setting. Registered plugins are consulted before the navigation guard runs, so a small plugin can block the path. On Android, override `shouldOverrideLoad(Uri url)` and return `true` when `url.getPath()` starts with `/_capacitor_http_interceptor_`. On iOS, implement `shouldOverrideLoad(_:)` and return `true` for the same path. Returning `true` cancels the navigation; return `null`/`nil` for all other URLs so normal navigation is unchanged. Independently, sanitize user-controlled link targets before rendering them in the WebView.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @capacitor/android 6.2.2, @capacitor/android 7.6.9, @capacitor/ios 6.2.2, @capacitor/ios 7.6.9, github.com/ionic-team/capacitor-swift-pm 6.2.2, github.com/ionic-team/capacitor-swift-pm 7.6.9, com.capacitorjs:core 6.2.2, com.capacitorjs:core 7.6.9, @capacitor/android 8.5.1, @capacitor/ios 8.5.1, github.com/ionic-team/capacitor-swift-pm 8.5.1, com.capacitorjs:core 8.5.1, com.capacitorjs:core 8.4.3, @capacitor/android 8.4.3, @capacitor/ios 8.4.3, github.com/ionic-team/capacitor-swift-pm 8.4.3.
Technical details
- Vendor
- Not specified
- Product
- @capacitor/android, @capacitor/ios, github.com/ionic-team/capacitor-swift-pm, com.capacitorjs:core
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source