Android WebView debugging enabled

Android WebView debugging enabled

Description

Enabling WebView.setWebContentsDebuggingEnabled(true) in a production build allows WebView pages, storage, and network activity to be inspected through USB debugging or a debug connection. Sensitive session information and DOM data may be exposed.

Potential impact

  • Disclosure of WebView storage and session information.
  • Page manipulation or script execution.
  • Inspection of the production app's internal behavior.

Remediation

  1. Enable debugging only under a BuildConfig.DEBUG condition.
  2. Explicitly disable it in release builds or remove the enabling call.
  3. Verify that the release build sets debuggable=false.

Examples

Before

java
WebView.setWebContentsDebuggingEnabled(true);

After

java
if (BuildConfig.DEBUG) {
    WebView.setWebContentsDebuggingEnabled(true);
}

Explanation:

  • Before: Connected developer tools can inspect WebView content and its JavaScript context when debugging is enabled.
  • After: In production builds, use WebView.setWebContentsDebuggingEnabled(false) or omit the enabling call, together with the release build settings described above.

References