Description
Passing a script built through concatenation or interpolation to WKWebView.evaluateJavaScript can cause external input to execute as JavaScript, allowing code injection in the WebView context.
Potential impact
- JavaScript injection in the WebView
- Theft of local data
- Manipulation of user sessions or displayed content
Remediation
- Pass only static scripts to
evaluateJavaScript. - Supply external data through APIs that separate it from code, such as the
argumentsdictionary ofcallAsyncJavaScript. - Do not concatenate or interpolate user input into JavaScript source strings.
Examples
Before
swift
webView.evaluateJavaScript("console.log(" + remoteData + ")")
After
swift
try await webView.callAsyncJavaScript(
"console.log(data)",
arguments: ["data": remoteData],
contentWorld: .page
)
Explanation:
- Before: External data is concatenated into JavaScript source and executed.
- After: Code and data are passed separately.