Description
Enabling WebView.setWebContentsDebuggingEnabled(true) in a production build allows WebView pages, storage, and network activity to be inspected through USB debugging or a debug connection. Sensitive session information and DOM data may be exposed.
Potential impact
- Disclosure of WebView storage and session information.
- Page manipulation or script execution.
- Inspection of the production app's internal behavior.
Remediation
- Enable debugging only under a
BuildConfig.DEBUGcondition. - Explicitly disable it in release builds or remove the enabling call.
- Verify that the release build sets
debuggable=false.
Examples
Before
java
WebView.setWebContentsDebuggingEnabled(true);
After
java
if (BuildConfig.DEBUG) {
WebView.setWebContentsDebuggingEnabled(true);
}
Explanation:
- Before: Connected developer tools can inspect WebView content and its JavaScript context when debugging is enabled.
- After: In production builds, use
WebView.setWebContentsDebuggingEnabled(false)or omit the enabling call, together with the release build settings described above.