logo

Critical Cordova Vulnerability Threatens iOS App Data Boundaries

ID: 0c394de6-8983-531c-9d30-b11f24dd4922

STIX ID: report--0c394de6-8983-531c-9d30-b11f24dd4922

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-07

Date Updated: 2026-06-07

Author: Do Son

...
...

Severe vulnerability CVE-2026-47430 in Apache Cordova's iOS InAppBrowser plugin allows untrusted web content to break out of the sandbox and trigger predictable host-app callbacks, enabling remote unauthenticated attackers to execute commands, spoof plugin results, and access sensitive device capabilities; versions 3.1.0 through 6.0.0 are affected and immediate upgrade to 6.0.1 (which adds validation) is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.