https://seclists.org/oss-sec/2026/q2/829: CVE-2026-47430: Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews
Published Jun 7, 2026
·Updated
Affected Software
1 affected component
npm/cordova-plugin-inappbrowser>=3.1.0<=6.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-47430?
The severity of CVE-2026-47430 is classified as important.
2
Which versions of Cordova Plugin InAppBrowser are affected by CVE-2026-47430?
CVE-2026-47430 affects Cordova Plugin InAppBrowser versions from 3.1.0 through 6.0.0.
3
What vulnerability does CVE-2026-47430 describe?
CVE-2026-47430 describes a vulnerability where arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
4
How do I fix CVE-2026-47430?
To fix CVE-2026-47430, update the Cordova Plugin InAppBrowser to a version above 6.0.0.
5
What impact does CVE-2026-47430 have on iOS applications?
CVE-2026-47430 can lead to improper execution of arbitrary commands in iOS applications using the affected versions of the InAppBrowser.