Android WebView ignores certificate errors

Ignoring Android WebView certificate errors

Description

Calling handler.proceed() in WebViewClient.onReceivedSslError lets WebView continue loading despite a TLS certificate error. In production, this can enable a man-in-the-middle attack and make untrusted content appear legitimate.

Potential impact

  • Interception or modification of HTTPS traffic.
  • Disclosure of login credentials and session tokens.
  • Injection of malicious scripts.

Remediation

  1. Call handler.cancel() when a certificate error occurs and stop loading.
  2. For a development server's test certificate, use Network Security Config debug-overrides to trust the test CA only in debug builds. Do not ignore certificate errors.
  3. If certificate pinning is required, review Android Network Security Config.

Examples

Before

java
public void onReceivedSslError(WebView view, SslErrorHandler handler, SslError error) {
    handler.proceed();
}

After

java
public void onReceivedSslError(WebView view, SslErrorHandler handler, SslError error) {
    handler.cancel();
}

Explanation:

  • Before: handler.proceed() ignores the TLS certificate error and continues loading the page.
  • After: handler.cancel() stops loading when a certificate error occurs.

References