Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-rvm3-566m-v7fv
Impact
Capacitor's WebView navigation guard validated only the host and scheme of a
target URL, not its path. Because the internal HTTP proxy path
(/_capacitor_http_interceptor_) is served at the application's own origin, a
frame navigation to it was always treated as in-app navigation and allowed.
Loading that path as a document caused the native layer to fetch an arbitrary,
caller-specified URL and return the response body to the WebView at the app's
own origin. Script in that response then ran with full same-origin trust:
access to localStorage, cookies, and every native capability the application
exposes through its registered Capacitor plugins.
The proxy handler was additionally served regardless of whether the
CapacitorHttp plugin was enabled, so applications that never enabled
CapacitorHttp were also affected.
Exploitation requires a victim to activate a link inside the application's WebView. Any Capacitor application that renders user-controlled or unsanitized links (chat messages, comments, rich-text content) is a viable delivery surface.
Both Android and iOS are affected.
Patches
Two changes on each platform:
- The navigation guard now blocks frame navigations whose path is the internal proxy path.
- The proxy handler is served only when
CapacitorHttpis enabled, and never for a document (main frame) request.
Legitimate CapacitorHttp usage is unaffected. fetch and XMLHttpRequest are
subresource requests and do not pass through the navigation guard.
Upgrade to a patched version, then rebuild and redistribute your application.
Workarounds
If you cannot upgrade immediately, note first that disabling CapacitorHttp
is not sufficient on affected versions, because the proxy path is served
regardless of that setting.
Registered plugins are consulted before the navigation guard runs, so a small
plugin can block the path. On Android, override shouldOverrideLoad(Uri url) and
return true when url.getPath() starts with /_capacitor_http_interceptor_.
On iOS, implement shouldOverrideLoad(_:) and return true for the same path.
Returning true cancels the navigation; return null/nil for all other URLs
so normal navigation is unchanged.
Independently, sanitize user-controlled link targets before rendering them in the WebView.
Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.
Drag and drop some file here, or click to select
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. The attacker needs the user to perform some action, like clicking a link. The vulnerability can affect other systems as well, not just the initial system. There is a high impact on the confidentiality of the information. There is a high impact on the integrity of the data.
Exploitation activity has been observed. Apply available patches or mitigations urgently.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard