Executive brief
Cap-go capacitor-updater is a tool used by developers to push live updates to mobile applications. A security flaw in its encryption system allows unauthorized parties to potentially distribute malicious app updates to users' devices. This could occur if an attacker intercepts network traffic or compromises the update server, leading to the installation of fraudulent software that could steal data or disrupt app operations.
Technical details
A vulnerability exists in @capgo/capacitor-updater before version 12.128.2 due to improper key management (CWE-320). The end-to-end encryption implementation incorrectly distributes the private key to every device that downloads the application. Since the public key can be derived from this private key, an attacker capable of a man-in-the-middle (MITM) attack or a server-side compromise can generate validly signed update bundles. This allows the attacker to bypass integrity checks and force devices to install arbitrary, malicious updates. The issue is addressed in version 12.128.2.
Affected products
- Cap-go capacitor-updater < 12.128.2
Timeline
- 2026-02-10: advisory: Initial GitHub Security Advisory published
- 2026-07-10: disclosed: CVE-2026-56254 published