Sceawere
Vulnerability Detail
CVE-2026-103922UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Capacitor WebView Navigation Proxy Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 1d ago
- Vendor
- ionic-team
- Product
- capacitor
- Attack Type
- CWE-346: Origin Validation Error
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the response as a document at the application's own origin, allowing script in that response to access same-origin storage, cookies, and registered Capacitor plugin capabilities. Applications remain affected when CapacitorHttp is disabled because affected releases serve the proxy path regardless of that setting. This issue is fixed in versions 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-01T18:17:12.840Z",
"pubdate": "2026-10-01T18:17:12.840Z",
"executiveSummary": "Capacitor is susceptible to a cross-origin security vulnerability within its WebView navigation guard mechanism on Android and iOS platforms.\nThe vulnerability stems from insufficient validation of target URL paths during navigation, enabling an attacker to force the WebView to interact with the internal '_capacitor_http_interceptor_' path.\nBy redirecting a frame to this internal endpoint, an attacker can coerce the native proxy to fetch arbitrary external content and inject it into the application's origin.\nSuccessful exploitation grants an attacker the ability to execute malicious scripts within the context of the application, resulting in full access to same-origin storage, sensitive cookies, and authorized Capacitor plugin capabilities.\nThis vulnerability poses a significant risk as it persists even when the CapacitorHttp feature is explicitly disabled, as the underlying interceptor path remains active.\nAffected releases include versions 6.0.0 through 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1. Users are advised to upgrade to the designated patched versions immediately.",
"technicalDetails": "The root cause of this vulnerability lies in the flawed logic of the WebView navigation guard within the Capacitor native runtime. While the implementation correctly performs validation checks on the host and scheme components of a navigation request, it neglects to inspect or restrict the path component. This omission allows an attacker to navigate the WebView frame to a specific internal path: '/_capacitor_http_interceptor_'.\nUnder normal operations, the native proxy uses this internal path to facilitate authorized HTTP traffic. However, because the navigation guard fails to filter this path, an untrusted link can trigger the proxy to process an attacker-supplied URL. The native bridge then fetches the remote content and presents the response to the WebView as if it originated from the application's own origin.\nThe attack flow begins when a victim is coerced into activating an untrusted link—often via social engineering or a malicious advertisement—that directs the WebView to the '/_capacitor_http_interceptor_' endpoint. Once the internal handler is invoked, it treats the attacker-controlled input as a legitimate request target. The native layer performs the fetch and returns the payload to the WebView environment.\nBecause the resulting content is rendered within the application's origin, the browser's Same-Origin Policy (SOP) is effectively bypassed. The injected script inherits the application's security context, allowing it to read, modify, or exfiltrate data from LocalStorage, SessionStorage, and IndexedDB. Furthermore, the script gains access to the application's bridge-registered Capacitor plugins, potentially allowing the attacker to interact with device hardware, file systems, or native APIs authorized for the application.\nThis exploit does not require the attacker to have pre-existing authentication or specific privileges beyond the ability to influence the navigation target within the WebView. The threat is global to the application context; regardless of whether CapacitorHttp is disabled in the configuration, the interceptor path remains reachable, meaning the exposure is constant for all applications running the affected library versions.\nExploitation is platform-agnostic, affecting both Android and iOS implementations of the Capacitor WebView, as the underlying architecture shares the same logic flaw in the navigation interceptor."
}