
CVE-2026-103922 hits ionic-team's Capacitor on Android and iOS, CVSS 9.3. The navigation guard checks a link's host and scheme but not its path, so a victim who taps a crafted link loads attacker content through the internal HTTP proxy, served back as the app's own origin with its storage, cookies and plugin access. VulnTracker recommends upgrading to 6.2.2, 7.6.9, 8.3.5, 8.4.3 or 8.5.1 now, disabling CapacitorHttp does not protect you. Details: http://vulntracker.io/cves/CVE-2026-103922 #Capacitor #MobileSecurity #CVE #InfoSec

