Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Capacitor

Capacitor Vendor Cyber Rating & Cyber Score

capacitorcareers.co.uk

We aim to enhance digital employability and focus on providing internships, start up internships and entry level digital positions.


Capacitor A.I CyberSecurity Scoring

Capacitor
Company Information
Website:http://www.capacitorcareers.co.uk
Employees number:3
Number of followers:56
NAICS:519131
Industry Type:Online Audio and Video Media
Homepage:capacitorcareers.co.uk
Capacitor Risk Score (AI oriented)
Between 700 and 749
logo
CapacitorOnline Audio and Video Media
Updated:
02/10/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Capacitor Global Score (TPRM)
xxxx
logo
CapacitorOnline Audio and Video Media
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CapacitorModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
753Before Incident
Vulnerability
02 Oct 2026 • Capacitor
Capacitor: Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust

Critical Capacitor Vulnerability (CVE-2026-103922) Exposes Mobile Apps to Remote Code Execution

749After Incident
CRITICAL-4
CAP1790944040
Critical Capacitor Vulnerability (CVE-2026-103922) Exposes Mobile Apps to Remote Code Execution A high-severity vulnerability (CVE-2026-103922, CVSS 9.3) in Capacitor, a cross-platform framework for building Android and iOS applications, allows attackers to execute malicious code within vulnerable apps under the guise of a trusted origin. The flaw stems from insufficient validation in Capacitor’s WebView navigation guard, which fails to properly verify URL paths, enabling exploitation of an internal proxy endpoint (`/_capacitor_http_interceptor_`). ### How the Exploit Works By tricking a user into clicking a malicious link within an app’s WebView, attackers can force the app to fetch attacker-controlled content via the proxy endpoint. The response is then rendered as a document under the app’s same-origin policy, granting malicious JavaScript access to: - Same-origin data (cookies, `localStorage`) - Native device functionality (via Capacitor plugins) - Sensitive app operations (authentication tokens, API interactions) The vulnerability affects apps regardless of whether the CapacitorHttp plugin is enabled, as the proxy endpoint remains accessible in vulnerable versions. ### Affected Versions & Fixes The flaw impacts: - Capacitor 6.x (6.0.0–6.2.1) - Capacitor 7.x (7.0.0–7.6.8) - Capacitor 8.x (multiple pre-patch releases) Patched versions are available: - 6.2.2, 7.6.9, 8.3.5, 8.4.3, 8.5.1 The fix blocks navigation to the proxy endpoint and restricts its availability to when CapacitorHttp is explicitly enabled, while preserving legitimate subresource requests (e.g., `fetch`, `XMLHttpRequest`). ### Mitigation & Impact Developers must upgrade Capacitor, rebuild affected apps, and redistribute updates. Temporary workarounds include: - Plugin overrides to block navigation to `/_capacitor_http_interceptor_` - Sanitizing user-controlled links in WebViews (e.g., chat messages, embedded content) The vulnerability (tracked as CWE-346 and CWE-441) poses significant risks to apps handling sensitive data or native device features, with potential for data theft, unauthorized API access, or device compromise.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Same-origin data (cookies, localStorage), authentication tokens, API interactionsSystems Affected: Mobile apps built with vulnerable Capacitor versions (Android/iOS)Operational Impact: Unauthorized access to native device functionality, potential data theft, API abuseBrand Reputation Impact: Potential loss of user trust in affected appsIdentity Theft Risk: High (if PII or authentication tokens are exposed)
DATA BREACH
Same-origin data (cookies, localStorage)Authentication tokensAPI interactionsSensitivity Of Data: High (PII, authentication tokens, native device access)Data Exfiltration: Possible (via malicious JavaScript execution)Personally Identifiable Information: Possible (if stored in same-origin data)
SEPTEMBER 2026
753Before Incident
AUGUST 2026
753Before Incident
JULY 2026
753Before Incident
JUNE 2026
753Before Incident
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Capacitor ?
?
What was Capacitor's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Capacitor's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Capacitor's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Capacitor ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Capacitor's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?