TL;DR
A critical Capacitor vulnerability, CVE-2026-103922, scores 9.3 on CVSS and affects a framework with over 5.5 million weekly npm downloads. One tap on a malicious link can let an attacker run script with the app’s own origin. Patched releases are available for the 6.x, 7.x, and 8.x branches.
- CVE: CVE-2026-103922
- CVSS: 9.3 (Critical · CVSSv3)
- Product: ionic-team capacitor
- Affected: >= 6.0.0, < 6.2.2, >= 7.0.0, < 7.6.9, >= 8.0.0, < 8.3.5, >= 8.3.5, < 8.4.3, >= 8.5.0, < 8.5.1
- Impact: Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Running Infra, AppSec, and SOC teams? Tag Google alerts by team automatically.
Try Team free for 14 daysWhy It Matters
Ionic’s Capacitor lets developers ship one web codebase as native iOS, Android, and web apps. Its npm package sees over 5.5 million downloads each week, according to npm statistics. As a result, the flaw could reach a large number of mobile apps and their users.
The impact is broad. Script that runs at the app’s origin can read storage and cookies. It can also call any Capacitor plugin the app registers, such as camera or file access. No public proof-of-concept has been reported.
How the Attack Works
Capacitor’s WebView navigation guard checks a link’s host and scheme. However, it does not check the path. A crafted link can therefore point a frame at Capacitor’s internal HTTP proxy route.
That native proxy then fetches a URL the attacker chooses. Next, it returns the response as if it came from the app itself. The victim only needs to tap an untrusted link.
Notably, turning off CapacitorHttp does not help. Affected releases serve the proxy path regardless of that setting.
Affected Versions
- 6.0.0 up to 6.2.2
- 7.0.0 up to 7.6.9
- 8.0.0 up to 8.4.3
- 8.5.0 up to 8.5.1
The bug hits the Android, iOS, and Swift Package Manager builds alike.
Patch and Mitigation Steps
Developers should upgrade to 6.2.2, 7.6.9, 8.4.3, or 8.5.1, per the Capacitor GHSA-rvm3-566m-v7fv advisory. After that, rebuild and ship new app versions to the stores. If you cannot upgrade immediately, note first that disabling CapacitorHttp is not sufficient on affected versions, because the proxy path is served regardless of that setting. Finally, avoid opening untrusted links inside the app WebView until users update.
This Capacitor vulnerability lives in shipped apps, so a library update alone is not enough. Every affected app needs a new release.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!