Description
Enabling JavaScript in WebView lets loaded pages execute scripts. Used with untrusted URLs, HTML built from user input, or exposed JavaScript interfaces, it increases the risk of XSS, session theft, and misuse of internal app APIs.
Potential impact
- XSS execution within WebView.
- Disclosure of cookies, tokens, or local-storage values.
- Misuse of app functionality through
addJavascriptInterface.
Remediation
- Disable JavaScript in WebViews that do not need it.
- If JavaScript is required, load only trusted domains and restrict navigation.
- Do not insert user input as HTML; apply appropriate escaping.
Examples
Before
java
webView.getSettings().setJavaScriptEnabled(true);
webView.loadUrl(userControlledUrl);
After
java
webView.getSettings().setJavaScriptEnabled(false);
webView.loadUrl("https://example.com/help");
Explanation:
- Before: JavaScript runs in the context of the page loaded by WebView.
- After: Use
setJavaScriptEnabled(false)when JavaScript is unnecessary.