Ionic Capacitor CVE-2026-103922 (CVSS 9.3): WebView path bypass loads remote content at app origin; patch 6.2.2/7.6.9/8.3.5+/8.5.1
GitHub Security Advisory GHSA-rvm3-566m-v7fv / CVE-2026-103922 (published 1 October 2026; GitHub CNA CVSS 3.1 9.3 Critical; CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N): Capacitor Android/iOS WebView navigation guard validated host and scheme but not path. A victim who opens an untrusted link inside an affected app can navigate a frame to /_capacitor_http_interceptor_; the native HTTP proxy fetches attacker-chosen remote content and returns it as a document at the application origin, giving same-origin access to localStorage, cookies, and registered Capacitor plugin APIs (device data, tokens, files — plugin-dependent). Disabling CapacitorHttp does not mitigate on vulnerable builds because the proxy path was still served. Affected: >=6.0.0 <6.2.2, >=7.0.0 <7.6.9, >=8.0.0 <8.3.5, >=8.3.5 <8.4.3, >=8.5.0 <8.5.1. Fixed in 6.2.2, 7.6.9, 8.3.5, 8.4.3, 8.5.1 — rebuild and redistribute mobile apps. Wire: Cyber Security News 2 Oct. Primary: Ionic/GitHub GHSA-rvm3-566m-v7fv.
- Product
- Ionic Capacitor (Android/iOS WebView; @capacitor/android, @capacitor/ios, com.capacitorjs)
- Versions
- Affected: >=6.0.0 <6.2.2; >=7.0.0 <7.6.9; >=8.0.0 <8.3.5; >=8.3.5 <8.4.3; >=8.5.0 <8.5.1 (per GitHub CNA / GHSA).
- CVSS
CVE-2026-103922CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N- Exploited in Australia?
- unknown
- Patch to
- Upgrade Capacitor platform packages to 6.2.2 / 7.6.9 / 8.3.5 or 8.4.3 / 8.5.1 (match your major), rebuild Android/iOS apps, and redistribute. Until patched: sanitize/validate user-controlled URLs before WebView render; custom plugin rejecting navigations to /_capacitor_http_interceptor_ is a temporary control only.
Primary: GitHub Advisory GHSA-rvm3-566m-v7fv — Capacitor WebView origin bypass (CVE-2026-103922; 1 Oct 2026) · Vendor: ionic-team/capacitor — GHSA-rvm3-566m-v7fv · CVE: CVE-2026-103922 · Cyber Security News — Critical Capacitor WebView flaw (2 Oct 2026)
