CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103922

CRITICALCVSS 9.3NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-103922 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103922

CRITICALCVSS 9.3NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]