Vulnerabilities/

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser

Severity:
High

Description

The iOS implementation of cordova-plugin-inappbrowser passes the id field from a WKScriptMessage body to commandDelegate sendPluginResult:callbackId: with no format validation (CDVWKInAppBrowser.m:560–574).

Recommendation

Update the cordova-plugin-inappbrowser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
cordova-plugin-inappbrowser
Anything's wrong? Let us know Last updated on June 12, 2026