Critical Flaw in Capacitor Lets Malicious Links Hijack App Data

A serious vulnerability has been discovered in Capacitor on Android and iOS, allowing attacker-controlled web content loaded via malicious links opened inside a compromised mobile app to access sensitive data and native features. The issue—identified as CVE-2026-103922—has earned a CVSS score of 9.6, indicating a severe security risk. It stems from a weakness in how Capacitor’s WebView navigation protection handles internal URL paths.

How the Vulnerability Works

The flaw involves how Capacitor verifies navigation inside its WebView component. The system checks only the URL scheme (such as http or https) and host, but fails to validate the path portion of the URL properly. This oversight permits an attacker to craft a link pointing to the internal path /capacitor_http_interceptor—hosted at the app’s own origin—while pointing to a remote resource controlled by the attacker. Once the victim clicks the link within the app’s WebView, the app’s native layer fetches the external content and returns it under the app’s trusted origin.

Because the malicious content is served from the app’s own origin, it gains same-origin privileges. That grants it access to things like localStorage and cookies, along with access to any native functionality exposed through Capacitor plugins—potentially including device data, files, notifications, authentication tokens, and more.

Which Versions Are Affected & What’s the Fix?

The vulnerability affects a wide range of Capacitor versions: all versions from 6.0.0 up to, but not including, 6.2.2; versions 7.0.0 up to 7.6.9; and from 8.0.0 to before 8.3.5; also 8.3.5 to before 8.4.3; and 8.5.0 to before 8.5.1.

The patched releases address the issue in several ways: navigation to the internal proxy path is now blocked in frame navigations; the proxy handler only activates when the CapacitorHttp plugin is enabled; responses no longer apply to document or main-frame requests. Legitimate uses of fetch or XMLHttpRequest remain unaffected. Developers are urged to upgrade to the fixed versions, rebuild their apps for Android and iOS, and push updates to users.

Workarounds and Mitigations

For organizations unable to update immediately, there are temporary mitigation steps. One is implementing a custom Capacitor plugin that rejects navigation attempts targeting /capacitor_http_interceptor. Another is sanitizing and strictly validating any user-controlled URLs before rendering them inside a WebView. Disabling the CapacitorHttp plugin alone does not guard against exploitation; the proxy handler remains available even when that plugin is off in vulnerable versions.

This vulnerability is especially risky for apps that render user-provided links—such as chat apps, comment feeds, in-app browsers, or any feature that allows external links inside the app. A user’s click inside such environments is all that’s needed to trigger the exploit.

Why this matters:Capacitor is a popular cross-platform framework used to build hybrid mobile apps. The integrity of its WebView navigation guard is central to its security model. A flaw here can undermine app trust boundaries, potentially exposing private data or device features to attackers via what look like ordinary links.

What to watch for:Developer teams using Capacitor should audit their versions immediately, check whether their apps display user-supplied links, and enforce URL validation rigorously. Upgrading to the patched releases is essential. For security-conscious organizations, testing to ensure proxy handlers are disabled when not in use—and that WebView navigations to the internal proxy path are blocked—will be critical to mitigate risk until updates are rolled out.