Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust

A critical vulnerability in Capacitor, identified as CVE-2026-103922, could allow attacker-controlled remote content to execute within vulnerable Android and iOS applications, posing as the application’s own trusted origin. This flaw, assigned a CVSS score of 9.3, affects WebView navigation handling in Capacitor and can expose same-origin data, cookies, local storage, and native functionality available through […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: