Guide

Critical Capacitor Flaw Lets Malicious Links Steal App Data Under Native Origin Trust

A critical bug in Capacitor, the framework behind a large share of hybrid iOS and Android apps, lets a single malicious link load attacker code that the ap

A critical bug in Capacitor, the framework behind a large share of hybrid iOS and Android apps, lets a single malicious link load attacker code that the app treats as its own. Tracked as CVE-2026-103922 and scored CVSS 9.6, it breaks the trust boundary that hybrid apps quietly depend on.

Capacitor apps run web code inside a WebView and bridge it to native features through plugins. A navigation guard is supposed to keep outside content from posing as the app. The problem is that the guard checked the scheme and host of a URL but never the path.

That gap points straight at /capacitor_http_interceptor, an internal proxy route served at the app's own origin. An attacker can navigate the WebView there while supplying an arbitrary remote URL. Capacitor's native layer then fetches the attacker's content and serves it as if it came from the legitimate app.

Once that happens, the injected scripts get same-origin access to localStorage, cookies and whatever native Capacitor plugins the app has registered. Depending on the app, that can mean auth tokens, files, device data and notifications.

Exploitation does need a user to open the malicious link inside the WebView. That sounds like a high bar until you think about where links show up: chat threads, comment sections, support portals, social feeds and in-app browsers. Any app that renders user-controlled links is especially exposed, and the internal proxy handler stays reachable even when the CapacitorHttp plugin is disabled.

It is the same uncomfortable lesson as the FortiMail zero-day and the Milk Dragon kit that walks past OTP MFA: the dangerous part is rarely the obvious front door, it is the component everyone assumed was internal and trusted.

Affected versions are 6.0.0 before 6.2.2, 7.0.0 before 7.6.9, 8.0.0 before 8.3.5, 8.3.5 before 8.4.3, and 8.5.0 before 8.5.1. The fix now blocks frame navigations to the interceptor path and only serves the proxy when CapacitorHttp is actually enabled.

Patching is not a server-side switch. Developers have to upgrade, rebuild and push a new release through the app stores, and users have to install it. Until then, the stopgap is a custom plugin that rejects navigations to /capacitor_http_interceptor, plus sanitizing any user-controlled URL before the WebView ever touches it.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free