[Critical] CVE-2026-47430 – ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `...
Critical CVE-2026-47430 ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser...