← العودة للجدول
CVE-2026-47430
CVE-2026-47430 — GHSA: ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a ...
📅 2026-06-08
🔴 Critical 🔥 No GHSA Exploit iOS 🎯 EPSS 0.13%

📋 الوصف الكامل

## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser can fire any pending Cordova callback in the host app by posting a message whose `id` field is a guessable or enumerated c

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-47430

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←