Android WebView JavaScript enabled

Android WebView JavaScript enabled

Description

Enabling JavaScript in WebView lets loaded pages execute scripts. Used with untrusted URLs, HTML built from user input, or exposed JavaScript interfaces, it increases the risk of XSS, session theft, and misuse of internal app APIs.

Potential impact

  • XSS execution within WebView.
  • Disclosure of cookies, tokens, or local-storage values.
  • Misuse of app functionality through addJavascriptInterface.

Remediation

  1. Disable JavaScript in WebViews that do not need it.
  2. If JavaScript is required, load only trusted domains and restrict navigation.
  3. Do not insert user input as HTML; apply appropriate escaping.

Examples

Before

java
webView.getSettings().setJavaScriptEnabled(true);
webView.loadUrl(userControlledUrl);

After

java
webView.getSettings().setJavaScriptEnabled(false);
webView.loadUrl("https://example.com/help");

Explanation:

  • Before: JavaScript runs in the context of the page loaded by WebView.
  • After: Use setJavaScriptEnabled(false) when JavaScript is unnecessary.

References