Apache disclosed CVE-2026-47430, an important-severity vulnerability in the iOS implementation of cordova-plugin-inappbrowser that allows web content loaded inside an InAppBrowser WebView to dispatch arbitrary Cordova callback IDs without validation. The flaw stems from a crafted id field in a WKScriptMessage being passed into Cordova’s command handling, enabling untrusted content to trigger pending callbacks that should belong to other parts of the host app.
Because Cordova callback IDs are predictable, a remote attacker controlling displayed content or intercepting traffic could enumerate identifiers and spoof results for other installed plugins, including Camera, Contacts, File, and Geolocation. Reported by Niklas Merz and tracked as issue #1152, the bug affects cordova-plugin-inappbrowser versions 3.1.0 through 6.0.0 on iOS; Apache fixed it in 6.0.1, and exploitation scenarios may include malicious webpages, OAuth redirect flows, or deep links viewed inside affected apps.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability was fixed in cordova-plugin-inappbrowser version 6.0.1 by adding validation to prevent unauthorized callback execution. Users of affected iOS versions 3.1.0 through 6.0.0 were advised to upgrade.
Apache disclosed CVE-2026-47430, an important-severity flaw in the iOS implementation of cordova-plugin-inappbrowser that allows arbitrary Cordova callback IDs to be dispatched without validation from InAppBrowser WebViews. The issue affects versions 3.1.0 through 6.0.0 and was reported by Niklas Merz.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcesecurityonline.info
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.