GHSA-rvm3-566m-v7fv: Critical severity npm/@capacitor/ios vulnerability

Published Oct 5, 2026
·
Updated

Impact

Capacitor's WebView navigation guard validated only the host and scheme of a target URL, not its path. Because the internal HTTP proxy path (/capacitorhttpinterceptor) is served at the application's own origin, a frame navigation to it was always treated as in-app navigation and allowed.

Loading that path as a document caused the native layer to fetch an arbitrary, caller-specified URL and return the response body to the WebView at the app's own origin. Script in that response then ran with full same-origin trust: access to localStorage, cookies, and every native capability the application exposes through its registered Capacitor plugins.

The proxy handler was additionally served regardless of whether the CapacitorHttp plugin was enabled, so applications that never enabled CapacitorHttp were also affected.

Exploitation requires a victim to activate a link inside the application's WebView. Any Capacitor application that renders user-controlled or unsanitized links (chat messages, comments, rich-text content) is a viable delivery surface.

Both Android and iOS are affected.

Patches

Two changes on each platform:

1. The navigation guard now blocks frame navigations whose path is the internal proxy path. 2. The proxy handler is served only when CapacitorHttp is enabled, and never for a document (main frame) request.

Legitimate CapacitorHttp usage is unaffected. fetch and XMLHttpRequest are subresource requests and do not pass through the navigation guard.

Upgrade to a patched version, then rebuild and redistribute your application.

Workarounds

If you cannot upgrade immediately, note first that disabling CapacitorHttp is not sufficient on affected versions, because the proxy path is served regardless of that setting.

Registered plugins are consulted before the navigation guard runs, so a small plugin can block the path. On Android, override shouldOverrideLoad(Uri url) and return true when url.getPath() starts with /capacitorhttpinterceptor. On iOS, implement shouldOverrideLoad(:) and return true for the same path. Returning true cancels the navigation; return null/nil for all other URLs so normal navigation is unchanged.

Independently, sanitize user-controlled link targets before rendering them in the WebView.

Affected Software

20 affected componentsFixes available
npm/@capacitor/ios>=8.0.0<=8.3.4
npm/@capacitor/android>=8.0.0<=8.3.4
maven/com.capacitorjs:core>=8.0.0<=8.3.4
swift/github.com/ionic-team/capacitor-swift-pm>=8.0.0<=8.3.4
swift/github.com/ionic-team/capacitor-swift-pm>=8.3.5<8.4.3
8.4.3
npm/@capacitor/ios>=8.3.5<8.4.3
8.4.3
npm/@capacitor/android>=8.3.5<8.4.3
8.4.3
maven/com.capacitorjs:core>=8.3.5<8.4.3
8.4.3
maven/com.capacitorjs:core>=8.5.0<8.5.1
8.5.1
swift/github.com/ionic-team/capacitor-swift-pm>=8.5.0<8.5.1
8.5.1
npm/@capacitor/ios>=8.5.0<8.5.1
8.5.1
npm/@capacitor/android>=8.5.0<8.5.1
8.5.1
maven/com.capacitorjs:core>=7.0.0<7.6.9
7.6.9
maven/com.capacitorjs:core>=6.0.0<6.2.2
6.2.2
swift/github.com/ionic-team/capacitor-swift-pm>=7.0.0<7.6.9
7.6.9
swift/github.com/ionic-team/capacitor-swift-pm>=6.0.0<6.2.2
6.2.2
npm/@capacitor/ios>=7.0.0<7.6.9
7.6.9
npm/@capacitor/ios>=6.0.0<6.2.2
6.2.2
npm/@capacitor/android>=7.0.0<7.6.9
7.6.9
npm/@capacitor/android>=6.0.0<6.2.2
6.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade swift/github.com/ionic-team/capacitor-swift-pm to a version that resolves this vulnerability.

    Fixed in 8.4.3
  2. Upgrade

    Upgrade npm/@capacitor/ios to a version that resolves this vulnerability.

    Fixed in 8.4.3
  3. Upgrade

    Upgrade npm/@capacitor/android to a version that resolves this vulnerability.

    Fixed in 8.4.3
  4. Upgrade

    Upgrade maven/com.capacitorjs:core to a version that resolves this vulnerability.

    Fixed in 8.4.3
  5. Upgrade

    Upgrade maven/com.capacitorjs:core to a version that resolves this vulnerability.

    Fixed in 8.5.1
  6. Upgrade

    Upgrade swift/github.com/ionic-team/capacitor-swift-pm to a version that resolves this vulnerability.

    Fixed in 8.5.1
  7. Upgrade

    Upgrade npm/@capacitor/ios to a version that resolves this vulnerability.

    Fixed in 8.5.1
  8. Upgrade

    Upgrade npm/@capacitor/android to a version that resolves this vulnerability.

    Fixed in 8.5.1
  9. Upgrade

    Upgrade maven/com.capacitorjs:core to a version that resolves this vulnerability.

    Fixed in 7.6.9
  10. Upgrade

    Upgrade maven/com.capacitorjs:core to a version that resolves this vulnerability.

    Fixed in 6.2.2
  11. Upgrade

    Upgrade swift/github.com/ionic-team/capacitor-swift-pm to a version that resolves this vulnerability.

    Fixed in 7.6.9
  12. Upgrade

    Upgrade swift/github.com/ionic-team/capacitor-swift-pm to a version that resolves this vulnerability.

    Fixed in 6.2.2
  13. Upgrade

    Upgrade npm/@capacitor/ios to a version that resolves this vulnerability.

    Fixed in 7.6.9
  14. Upgrade

    Upgrade npm/@capacitor/ios to a version that resolves this vulnerability.

    Fixed in 6.2.2
  15. Upgrade

    Upgrade npm/@capacitor/android to a version that resolves this vulnerability.

    Fixed in 7.6.9
  16. Upgrade

    Upgrade npm/@capacitor/android to a version that resolves this vulnerability.

    Fixed in 6.2.2
  17. Configuration

    On Android, override shouldOverrideLoad(Uri url) and return true when url.getPath() starts with /_capacitor_http_interceptor_. On iOS, implement shouldOverrideLoad(_:) and return true for the same path; return null/nil for all other URLs.

    Capacitor WebView navigation guard shouldOverrideLoad = return true for paths starting with /_capacitor_http_interceptor_
  18. Compensating control

    Sanitize user-controlled link targets before rendering them in the WebView.

Event History

Oct 5, 2026
Advisory Published
via GitHub·10:53 PM
Data Sourced
via GitHub·10:53 PM
DescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203