External risk intelligence

Capacitor WebView Navigation Vulnerability Allows Origin Spoofing

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-103922

The vulnerability exists within the Capacitor native runtime for Android and iOS applications. It requires a user to interact with an untrusted link within the local mobile application context. This is a client-side execution issue, not a service or internet-facing infrastructure component, making public network exposure of the vulnerable surface inherently unlikely.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in Capacitor, a native runtime for web applications on Android and iOS. The issue allows a malicious link to potentially expose sensitive application data and functionality by misdirecting requests through a native proxy. While the exposure is unlikely due to the client-side nature of the vulnerability, the potential impact necessitates awareness.

  • App navigation flaw could expose data.
  • Affects mobile apps using web technology.
  • Confirm relevance and check affected apps.

Attack Path

How an attacker could exploit the issue

An attacker can trick a user into clicking a malicious link within a mobile application. This link navigates the app's web view to a special interceptor path. The application then fetches content from an attacker-controlled URL and displays it as if it originated from the app itself, allowing malicious scripts to steal sensitive information or misuse app features.

  • Requires user interaction with a malicious link.
  • Navigates to an interceptor to fetch attacker content.
  • Compromises sensitive data and app capabilities.

Live Threat

Current exploitation, exposure, and threat context

When a user interacts with an untrusted link, an application could be tricked into fetching and displaying content from an attacker-controlled URL. This displayed content could then access the application's same-origin storage, cookies, and Capacitor plugin capabilities, potentially exposing sensitive information or altering application behavior.

  • Application data and cookies at risk.
  • Malicious links could trigger data exposure.
  • Sensitive information may be accessed.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Capacitor runtime's vulnerability impacts Android and iOS applications, making application owners and platform teams the likely first responders. The immediate practical step is to inventory all applications using affected Capacitor versions, identify business-critical apps, and confirm external link exposure. Subsequently, coordinate remediation with the relevant application and platform owners.

  • Application owners should manage the issue.
  • Verify external link handling in apps.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Capacitor and how is it used?

Capacitor is a developer tool used to create cross-platform mobile apps. It acts as a native runtime, allowing web technologies like HTML, CSS, and JavaScript to run inside a native wrapper on both Android and iOS devices. Developers use it to bridge web-based interfaces with native mobile features, enabling applications to interact with device hardware and local storage while maintaining a unified codebase.

What does CVE-2026-103922 mean for my app?

This CVE describes an origin validation failure, specifically categorized as CWE-346 (Origin Validation Error) and CWE-441 (Unchecked Proxy). Because the navigation guard only checks a URL's host and scheme but misses the path, a malicious link can force the app to load an internal proxy path. This tricks the app into treating external, attacker-controlled content as if it were a legitimate part of the trusted application, effectively bypassing browser-based security boundaries.

How is this vulnerability triggered?

The issue is triggered when a user interacts with a specifically crafted, untrusted link from within the mobile application. If a user clicks this link, the app navigates to an internal interceptor path, which then fetches and displays external content at the application's origin. Notably, disabling the CapacitorHttp feature does not prevent this; the vulnerable proxy path remains active and exploitable regardless of that configuration setting.

Is my application vulnerable to this threat?

According to Halo Surface Signal, this vulnerability is a client-side issue rather than a traditional internet-facing infrastructure flaw. It requires execution within the local mobile application context. While any app on an affected version is technically susceptible, the primary risk involves users interacting with untrusted links inside the app. Assess if your applications allow external navigation or link rendering, as these are the primary vectors for this interaction.

How should I respond to this advisory?

Begin by auditing your application inventory to identify which mobile projects utilize the affected Capacitor versions. Once you have a list of impacted software, prioritize those that handle sensitive user data or utilize critical Capacitor plugin capabilities. Coordinate with your development teams to update these applications to the patched versions—6.2.2, 7.6.9, 8.3.5, 8.4.3, or 8.5.1—to ensure the navigation guard correctly validates all URL components.

References