Description
Unnecessarily enabling allowFileAccess, allowContentAccess, allowFileAccessFromFileURLs, or allowUniversalAccessFromFileURLs can allow WebView content to access local files or content-provider data. Combined with external content, this may expose internal app data.
Potential impact
- Disclosure of local files or content URI data.
- Bypass of permission boundaries through WebView.
- Exposure of sensitive information when combined with XSS.
Remediation
- Disable file or content access when it is not needed.
- Do not combine external web content and local file access in the same WebView.
- Explicitly provide only required URIs and apply Content Security Policy and input validation.
Examples
Before
java
webView.getSettings().setAllowFileAccess(true);
webView.getSettings().setAllowUniversalAccessFromFileURLs(true);
After
java
webView.getSettings().setAllowFileAccess(false);
webView.getSettings().setAllowContentAccess(false);
webView.getSettings().setAllowUniversalAccessFromFileURLs(false);
Explanation:
- Before: Allowing
file://orcontent://access increases the risk that loaded content can reach app-local files or content-provider data. - After:
setAllowFileAccess(false)andsetAllowContentAccess(false)disable file-system and content URI access; universal access from file URLs is also disabled. App resources underfile:///android_assetandfile:///android_resremain accessible independently of the file-access setting.