Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)

Critical Capacitor WebView Navigation Guard Bypass Lets (TL-2026-2894), also tracked as GHSA-rvm3-566m-v7fv, is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-10-04. It has no confirmed attribution, affects Ionic (ionic-team) Capacitor (@capacitor/android, @capacitor/ios, references 1 CVE (CVE-2026-103922), maps to 8 MITRE ATT&CK techniques (T1005, T1059.007, T1185), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-2894

Threat ID
TL-2026-2894
Also known as
GHSA-rvm3-566m-v7fv
Severity
CRITICAL
CVSS
9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-10-04
Last reviewed
2026-10-04
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, finance, health, retail, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in Critical Capacitor WebView Navigation Guard Bypass Lets

Malware and tooling: CapacitorHttp

Capacitor's WebView navigation guard validated a URL's scheme and host but not its path, so a link to the internal /_capacitor_http_interceptor_ endpoint makes the native proxy fetch an attacker-chosen URL and return it at the app's own origin. Script in that response runs with same-origin privileges (localStorage, cookies, native plugins). Fixed in Capacitor 6.2.2, 7.6.9, 8.3.5, 8.4.3 and 8.5.1; no in-the-wild exploitation was reported in the sources.

How Critical Capacitor WebView Navigation Guard Bypass Lets works

CVE-2026-103922 (GHSA-rvm3-566m-v7fv) is an origin-validation / confused-deputy flaw in Capacitor, the cross-platform native runtime for web apps on Android and iOS. The WebView navigation guard checked only the scheme and host of a navigation target and did not validate the URL path. An attacker can therefore craft a link that navigates the WebView (including frames) to the internal path /_capacitor_http_interceptor_ while supplying an arbitrary remote URL. Capacitor's internal HTTP proxy then fetches that URL natively and returns the response to the WebView at the application's own origin.

Because the attacker-controlled response is served from the app's legitimate origin, any script in it executes with full same-origin privileges: it can read localStorage and cookies (including authentication tokens) and call native Capacitor plugin capabilities, exposing app data and device features (device data, tokens, files, notifications and app functions, depending on installed plugins). Per the advisory, the proxy path operated regardless of whether the CapacitorHttp plugin was enabled, so disabling CapacitorHttp is NOT a mitigation on affected versions. Exploitation requires user interaction (the victim must activate the link inside the app's WebView), which makes apps that render user-controlled content (chat, comments, rich text, social feeds, in-app browsers) the most exposed.

Affected: @capacitor/android and @capacitor/ios (npm), com.capacitorjs:core (Maven) and github.com/ionic-team/capacitor-swift-pm (Swift) in ranges >=6.0.0 <6.2.2, >=7.0.0 <7.6.9, >=8.0.0 <8.3.5, >=8.3.5 <8.4.3 and >=8.5.0 <8.5.1. Fix design (two changes per the advisory): (1) the navigation guard now blocks frame navigations to the internal proxy path, and the check runs before plugin callbacks so a plugin cannot re-allow it; (2) the proxy handler is served only when CapacitorHttp is enabled and never for document requests (main frame or iframe, detected on Android via the Upgrade-Insecure-Requests header), with proxy responses additionally carrying a 'Content-Security-Policy: sandbox; frame-ancestors none' header. Legitimate fetch/XMLHttpRequest use is subresource traffic and is unaffected. Release notes for 6.2.2, 7.6.9, 8.4.3 and 8.5.1 list 'block navigation to the internal HTTP proxy path' and 'block the HTTP proxy path in subframes'. Because the framework is compiled into each app, downstream Android/iOS apps must be rebuilt and redistributed to be fixed.

Scoring note: the GitHub advisory and NVD record CVSS 3.1 base score 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N); the Cyber Security News article reports 9.6 with the same vector. This record uses the 9.3 from the advisory/NVD. NVD status at last check was 'Awaiting Analysis'. The sources report no known exploitation, no named threat actor, no public PoC code and no network IOCs.

MITRE ATT&CK techniques used in TL-2026-2894

Collection

T1005 Data from Local System; T1185 Browser Session Hijacking; T1636 Protected User Data

Execution

T1059.007 JavaScript; T1204.001 Malicious Link

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Initial Access

T1566.002 Spearphishing Link

Affected products and versions in Critical Capacitor WebView Navigation Guard Bypass Lets

  • Ionic (ionic-team) — Capacitor (@capacitor/android, @capacitor/ios, com.capacitorjs:core, capacitor-swift-pm)
    Vulnerable versions: >=6.0.0 <6.2.2; >=7.0.0 <7.6.9; >=8.0.0 <8.3.5; >=8.3.5 <8.4.3; >=8.5.0 <8.5.1
    Fixed in: 6.2.2; 7.6.9; 8.3.5; 8.4.3; 8.5.1

Remediation for Critical Capacitor WebView Navigation Guard Bypass Lets

Patches

  • Upgrade to Capacitor 6.2.2, 7.6.9, 8.3.5, 8.4.3 or 8.5.1 (matching your major line)
  • Rebuild and redistribute Android and iOS app builds after upgrading

Immediate actions

  • Inventory Android/iOS apps built on Capacitor and identify the Capacitor core version in each
  • Sanitize and validate user-controlled link targets before rendering them in the WebView

Workarounds

  • Register a custom Capacitor plugin that rejects navigations to paths starting with /_capacitor_http_interceptor_ (Android: override shouldOverrideLoad(Uri) and return true on that path prefix; iOS: implement shouldOverrideLoad(_:) with the same check; return null/nil for all other URLs)
  • Note: disabling the CapacitorHttp plugin is not sufficient on affected versions

Longer-term hardening

  • Avoid rendering untrusted or user-generated links/content inside the app WebView; open external links in the system browser
  • Monitor WebView navigations to unexpected paths on the app origin

CVEs associated with Critical Capacitor WebView Navigation Guard Bypass Lets

CVE-2026-103922

Weaknesses (CWE) in Critical Capacitor WebView Navigation Guard Bypass Lets

CWE-346, CWE-441

Timeline of Critical Capacitor WebView Navigation Guard Bypass Lets

  • GitHub Security Advisory GHSA-rvm3-566m-v7fv shows publication date August 31, 2026: describes the navigation guard bypass to /_capacitor_http_interceptor_, the two-part fix and a workaround plugin; credits andredestro for remediation development
  • Capacitor releases 6.2.2, 7.6.9, 8.4.3 and 8.5.1 published with the proxy-path navigation block (8.3.5 is listed as a fixed version; its release page was not retrievable)
  • Fix commits land in ionic-team/capacitor (authored by ItsChaceD): ee586ae 'block navigation to the internal HTTP proxy path' and 80b6c5e 'block the HTTP proxy path in subframes', moving the proxy-path block ahead of plugin callbacks and adding a CSP sandbox header to proxy responses; backports 430356a (7.x) and d5e3170 (6.x) follow
  • CVE-2026-103922 published in NVD (2026-10-01T18:17Z) with CVSS 3.1 base score 9.3 and CWE-346 / CWE-441, referencing GHSA-rvm3-566m-v7fv, the 8.5.1 release and six fix commits
  • Cyber Security News reports the flaw citing a CVSS of 9.6 (advisory and NVD list 9.3); describes malicious in-app link exploitation of chat, comments, social feeds and in-app browsers; no in-the-wild exploitation reported
  • NVD record for CVE-2026-103922 last modified (2026-10-02T18:44Z); vulnerability status remains Awaiting Analysis

Sources cited for Critical Capacitor WebView Navigation Guard Bypass Lets

More in vulnerability

Detection coverage for TL-2026-2894

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2894 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats