Vulnerability in Capacitor WebView Navigation Guard Affects Multiple Versions
CVE-2026-103922

9.3CRITICAL

Key Information:

Vendor

Ionic-team

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103922?

A security vulnerability exists in Capacitor WebView navigation guard, which does not properly validate the path of a target URL. This issue allows an attacker to leverage untrusted links that enable the navigation of a frame to /capacitor_http_interceptor. An attacker can use this exploit to fetch a malicious URL and execute scripts within the context of the application's origin, gaining access to sensitive data such as cookies and local storage. Notably, applications remain vulnerable even if the CapacitorHttp feature is disabled, as the proxy path is still served in the affected versions. This vulnerability is addressed in the latest updates.

Affected Version(s)

android >= 8.5.0, < 8.5.1 < 8.5.0, 8.5.1

android >= 8.3.5, < 8.4.3 < 8.3.5, 8.4.3

android >= 8.0.0, < 8.3.5 < 8.0.0, 8.3.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.