Description
Calling handler.proceed() in WebViewClient.onReceivedSslError lets WebView continue loading despite a TLS certificate error. In production, this can enable a man-in-the-middle attack and make untrusted content appear legitimate.
Potential impact
- Interception or modification of HTTPS traffic.
- Disclosure of login credentials and session tokens.
- Injection of malicious scripts.
Remediation
- Call
handler.cancel()when a certificate error occurs and stop loading. - For a development server's test certificate, use Network Security Config
debug-overridesto trust the test CA only in debug builds. Do not ignore certificate errors. - If certificate pinning is required, review Android Network Security Config.
Examples
Before
java
public void onReceivedSslError(WebView view, SslErrorHandler handler, SslError error) {
handler.proceed();
}
After
java
public void onReceivedSslError(WebView view, SslErrorHandler handler, SslError error) {
handler.cancel();
}
Explanation:
- Before:
handler.proceed()ignores the TLS certificate error and continues loading the page. - After:
handler.cancel()stops loading when a certificate error occurs.