App Bundle Selection Flaw in Capgo Software Allows Deployment of Deleted Versions
CVE-2026-56314
7.1HIGH
What is CVE-2026-56314?
Capgo software versions prior to 12.128.12 exhibit a vulnerability that allows attackers to exploit a missing filter in the /updates resolution process. This flaw enables the selection of deleted app versions, permitting the deployment of these discontinued bundles to devices. By bypassing the app_versions.deleted filter during channel version joins, malicious actors can manipulate the system and introduce vulnerabilities within the affected applications.
Affected Version(s)
Capgo 0 < 12.128.12
Capgo 12.128.12
