OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-103922: Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path

GitHub Advisories · officialPublished Oct 5, 2026Risk 50/100

### Impact Capacitor's WebView navigation guard validated only the **host and scheme** of a target URL, not its **path**. Because the internal HTTP proxy path (`/_capacitor_http_interceptor_`) is served at the application's own origin, a frame navigation to it was always treated as in-app navigation and allowed. Loading that path as a document caused the native layer to fetch an arbitrary, caller-specified URL and return the response body to the WebView **at the app's own origin**. Script in that response then ran with full same-origin trust: access to `localStorage`, cookies, and every native capability the application exposes through its registered Capacitor plugins. The proxy handler was additionally served **regardless of whether the `CapacitorHttp` plugin was enabled**, so applications that never enabled `CapacitorHttp` were also affected. Exploitation requires a victim to activate a link inside the application's WebView. Any Capacitor application that renders user-controlled or unsanitized links (chat messages, comments, rich-text content) is a viable delivery surface. Both **Android and iOS** are affected. ### Patches Two changes on each platform: 1. The navigation guard now blocks frame navigations whose path is the internal proxy path. 2. The proxy handler is served only when `CapacitorHttp` is enabled, and never for a document (main frame) request. Legitimate `CapacitorHttp` usage is unaffected. `fetch` and `XMLHttpRequest` are subresource requests and do not pass through the navigation guard. Upgrade to a patched version, then rebuild and redistribute your application. ### Workarounds If you cannot upgrade immediately, note first that **disabling `CapacitorHttp` is not sufficient** on affected versions, because the proxy path is served regardless of that setting. Registered plugins are consulted before the navigation guard runs, so a small plugin can block the path. On Android, override `shouldOverrideLoad(Uri url)` and return `true` when `url.getPath()` starts with `/_capacitor_http_interceptor_`. On iOS, implement `shouldOverrideLoad(_:)` and return `true` for the same path. Returning `true` cancels the navigation; return `null`/`nil` for all other URLs so normal navigation is unchanged. Independently, sanitize user-controlled link targets before rendering them in the WebView.

Upgrade affected packages to a patched version: @capacitor/android 6.2.2, @capacitor/android 7.6.9, @capacitor/ios 6.2.2, @capacitor/ios 7.6.9, github.com/ionic-team/capacitor-swift-pm 6.2.2, github.com/ionic-team/capacitor-swift-pm 7.6.9, com.capacitorjs:core 6.2.2, com.capacitorjs:core 7.6.9, @capacitor/android 8.5.1, @capacitor/ios 8.5.1, github.com/ionic-team/capacitor-swift-pm 8.5.1, com.capacitorjs:core 8.5.1, com.capacitorjs:core 8.4.3, @capacitor/android 8.4.3, @capacitor/ios 8.4.3, github.com/ionic-team/capacitor-swift-pm 8.4.3.

Vendor
Not specified
Product
@capacitor/android, @capacitor/ios, github.com/ionic-team/capacitor-swift-pm, com.capacitorjs:core
Exploitation
none known
Evidence
official
CVSS
9.3

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source