Android WebView file and content access allowed

Android WebView file or content access allowed

Description

Unnecessarily enabling allowFileAccess, allowContentAccess, allowFileAccessFromFileURLs, or allowUniversalAccessFromFileURLs can allow WebView content to access local files or content-provider data. Combined with external content, this may expose internal app data.

Potential impact

  • Disclosure of local files or content URI data.
  • Bypass of permission boundaries through WebView.
  • Exposure of sensitive information when combined with XSS.

Remediation

  1. Disable file or content access when it is not needed.
  2. Do not combine external web content and local file access in the same WebView.
  3. Explicitly provide only required URIs and apply Content Security Policy and input validation.

Examples

Before

java
webView.getSettings().setAllowFileAccess(true);
webView.getSettings().setAllowUniversalAccessFromFileURLs(true);

After

java
webView.getSettings().setAllowFileAccess(false);
webView.getSettings().setAllowContentAccess(false);
webView.getSettings().setAllowUniversalAccessFromFileURLs(false);

Explanation:

  • Before: Allowing file:// or content:// access increases the risk that loaded content can reach app-local files or content-provider data.
  • After: setAllowFileAccess(false) and setAllowContentAccess(false) disable file-system and content URI access; universal access from file URLs is also disabled. App resources under file:///android_asset and file:///android_res remain accessible independently of the file-access setting.

References