CVE-2026-103922 - Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path
CVE ID :CVE-2026-103922 Published : Oct. 1, 2026, 6:17 p.m. | 1 hour, 1 minute ago Description :Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host...