Executive brief
A vulnerability in the iOS version of the Cordova InAppBrowser plugin allows malicious websites loaded within the browser to interfere with the main mobile application. By guessing internal communication IDs, an attacker can trigger actions in other installed plugins, such as the camera, contacts, or file system. This could lead to unauthorized data access or the injection of fraudulent information into the app.
Technical details
The iOS implementation of cordova-plugin-inappbrowser lacks format validation for the 'id' field in WKScriptMessage bodies passed to 'commandDelegate sendPluginResult:callbackId:'. Because Cordova callback IDs follow a predictable '<PluginName><sequential-integer>' format, an unauthenticated remote attacker controlling content within the InAppBrowser can enumerate and fire pending callbacks for other plugins (e.g., Camera, Contacts, File). This allows for the injection of forged plugin results across trust boundaries. The vulnerability is fixed in version 6.0.1.
Affected products
- Apache cordova-plugin-inappbrowser >= 3.1.0, < 6.0.1
Timeline
- 2026-06-08: advisory: Initial disclosure and NVD publication
- 2026-06-12: other: GitHub Advisory reviewed and updated