CVE-2026-103922

CVE-2026-103922 is a critical-severity security vulnerability in @capacitor/android (npm), affecting versions >= 6.0.0, < 6.2.2. It is fixed in 6.2.2, 7.6.9, 8.5.1, 8.4.3.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path

Workarounds

If you cannot upgrade immediately, note first that disabling CapacitorHttp
is not sufficient
on affected versions, because the proxy path is served
regardless of that setting.

Registered plugins are consulted before the navigation guard runs, so a small
plugin can block the path. On Android, override shouldOverrideLoad(Uri url) and
return true when url.getPath() starts with /_capacitor_http_interceptor_.
On iOS, implement shouldOverrideLoad(_:) and return true for the same path.
Returning true cancels the navigation; return null/nil for all other URLs
so normal navigation is unchanged.

Independently, sanitize user-controlled link targets before rendering them in the
WebView.

Impact

Capacitor's WebView navigation guard validated only the host and scheme of a
target URL, not its path. Because the internal HTTP proxy path
(/_capacitor_http_interceptor_) is served at the application's own origin, a
frame navigation to it was always treated as in-app navigation and allowed.

Loading that path as a document caused the native layer to fetch an arbitrary,
caller-specified URL and return the response body to the WebView at the app's
own origin
. Script in that response then ran with full same-origin trust:
access to localStorage, cookies, and every native capability the application
exposes through its registered Capacitor plugins.

The proxy handler was additionally served regardless of whether the
CapacitorHttp plugin was enabled
, so applications that never enabled
CapacitorHttp were also affected.

Exploitation requires a victim to activate a link inside the application's
WebView. Any Capacitor application that renders user-controlled or unsanitized
links (chat messages, comments, rich-text content) is a viable delivery surface.

Both Android and iOS are affected.

CVE-2026-103922 has a CVSS score of 9.3 (Critical). The vector is network-reachable, no privileges required, and user interaction required. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (6.2.2, 7.6.9, 8.5.1, 8.4.3); upgrading removes the vulnerable code path.

Affected versions

@capacitor/android (>= 6.0.0, < 6.2.2) @capacitor/android (>= 7.0.0, < 7.6.9) @capacitor/ios (>= 6.0.0, < 6.2.2) @capacitor/ios (>= 7.0.0, < 7.6.9) github.com/ionic-team/capacitor-swift-pm (>= 6.0.0, < 6.2.2) github.com/ionic-team/capacitor-swift-pm (>= 7.0.0, < 7.6.9) com.capacitorjs:core (>= 6.0.0, < 6.2.2) com.capacitorjs:core (>= 7.0.0, < 7.6.9) @capacitor/android (>= 8.5.0, < 8.5.1) @capacitor/ios (>= 8.5.0, < 8.5.1) github.com/ionic-team/capacitor-swift-pm (>= 8.5.0, < 8.5.1) com.capacitorjs:core (>= 8.5.0, < 8.5.1) com.capacitorjs:core (>= 8.3.5, < 8.4.3) @capacitor/android (>= 8.3.5, < 8.4.3) @capacitor/ios (>= 8.3.5, < 8.4.3) github.com/ionic-team/capacitor-swift-pm (>= 8.3.5, < 8.4.3) github.com/ionic-team/capacitor-swift-pm (>= 8.0.0, <= 8.3.4) com.capacitorjs:core (>= 8.0.0, <= 8.3.4) @capacitor/android (>= 8.0.0, <= 8.3.4) @capacitor/ios (>= 8.0.0, <= 8.3.4)

Security releases

@capacitor/android → 6.2.2 (npm) @capacitor/android → 7.6.9 (npm) @capacitor/ios → 6.2.2 (npm) @capacitor/ios → 7.6.9 (npm) github.com/ionic-team/capacitor-swift-pm → 6.2.2 (swift) github.com/ionic-team/capacitor-swift-pm → 7.6.9 (swift) com.capacitorjs:core → 6.2.2 (maven) com.capacitorjs:core → 7.6.9 (maven) @capacitor/android → 8.5.1 (npm) @capacitor/ios → 8.5.1 (npm) github.com/ionic-team/capacitor-swift-pm → 8.5.1 (swift) com.capacitorjs:core → 8.5.1 (maven) com.capacitorjs:core → 8.4.3 (maven) @capacitor/android → 8.4.3 (npm) @capacitor/ios → 8.4.3 (npm) github.com/ionic-team/capacitor-swift-pm → 8.4.3 (swift)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

Two changes on each platform:

  1. The navigation guard now blocks frame navigations whose path is the internal
    proxy path.
  2. The proxy handler is served only when CapacitorHttp is enabled, and never
    for a document (main frame) request.

Legitimate CapacitorHttp usage is unaffected. fetch and XMLHttpRequest are
subresource requests and do not pass through the navigation guard.

Upgrade to a patched version, then rebuild and redistribute your application.

Frequently Asked Questions

  1. What is CVE-2026-103922? CVE-2026-103922 is a critical-severity security vulnerability in @capacitor/android (npm), affecting versions >= 6.0.0, < 6.2.2. It is fixed in 6.2.2, 7.6.9, 8.5.1, 8.4.3.
  2. How severe is CVE-2026-103922? CVE-2026-103922 has a CVSS score of 9.3 (Critical). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
  3. Which packages are affected by CVE-2026-103922?
    • @capacitor/android (npm) (versions >= 6.0.0, < 6.2.2)
    • @capacitor/ios (npm) (versions >= 6.0.0, < 6.2.2)
    • github.com/ionic-team/capacitor-swift-pm (swift) (versions >= 6.0.0, < 6.2.2)
    • com.capacitorjs:core (maven) (versions >= 6.0.0, < 6.2.2)
  4. Is there a fix for CVE-2026-103922? Yes. CVE-2026-103922 is fixed in 6.2.2, 7.6.9, 8.5.1, 8.4.3. Upgrade to this version or later.
  5. Is CVE-2026-103922 exploitable, and should I be worried? Whether CVE-2026-103922 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  6. What actually determines whether CVE-2026-103922 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  7. How do I fix CVE-2026-103922?
    • Upgrade @capacitor/android to 6.2.2 or later
    • Upgrade @capacitor/android to 7.6.9 or later
    • Upgrade @capacitor/ios to 6.2.2 or later
    • Upgrade @capacitor/ios to 7.6.9 or later
    • Upgrade github.com/ionic-team/capacitor-swift-pm to 6.2.2 or later
    • Upgrade github.com/ionic-team/capacitor-swift-pm to 7.6.9 or later
    • Upgrade com.capacitorjs:core to 6.2.2 or later
    • Upgrade com.capacitorjs:core to 7.6.9 or later
    • Upgrade @capacitor/android to 8.5.1 or later
    • Upgrade @capacitor/ios to 8.5.1 or later
    • Upgrade github.com/ionic-team/capacitor-swift-pm to 8.5.1 or later
    • Upgrade com.capacitorjs:core to 8.5.1 or later
    • Upgrade com.capacitorjs:core to 8.4.3 or later
    • Upgrade @capacitor/android to 8.4.3 or later
    • Upgrade @capacitor/ios to 8.4.3 or later
    • Upgrade github.com/ionic-team/capacitor-swift-pm to 8.4.3 or later

Stop the waste.
Protect your environment with Kodem.