Vulnary
← back to the feed
Critical· 9.5official fix available

CVE-2026-47430

The iOS version of Cordova’s InAppBrowser plugin fails to validate the callback ID sent from web content, letting a remote attacker trigger any Cordova plugin callback. This flaw allows an attacker to spoof plugin responses such as camera approvals or contact lists. The issue affects InAppBrowser versions 3.1.0 through 6.0.0.

publishedJun 8, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.5
critical · how bad it is
exploitation · epss
<1%
50th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 23, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Cordova Plugin InAppBrowser on iOS, versions 3.1.0‑6.0.0, used in mobile apps built with Apache Cordova.

02

Real-world impact

An attacker who can control the web page displayed in the InAppBrowser can send a crafted message that triggers any installed Cordova plugin’s callback, enabling them to forge data or actions—e.g., fake camera permissions, fabricated contacts, or manipulated file reads—without the user’s knowledge.

03

Why this severity

The CVSS score of 9.5 reflects the high impact of spoofing plugin results across trust boundaries and the remote, unauthenticated nature of the attack. The vulnerability is highly exploitable because the attacker only needs to load a malicious URL or intercept traffic to the InAppBrowser, and the predictable callback ID format makes enumeration straightforward.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the cordova-plugin-inappbrowser to version 6.0.1 or later.
  2. 02Restart the application to ensure the new plugin version is loaded.

NVD-referenced vendor advisory

05

Timeline

  1. Jun 8, 2026 · Jun 8, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 23, 2026 · 12d ago
    Advisory updated
    The NVD record was last revised.
  3. Jul 24, 2026 · 11d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityHigh
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →