How Threat Actors are Exploiting Android Webview
ID: 169fbcbe-7058-5f12-b4de-a914aa796d80
STIX ID: report--169fbcbe-7058-5f12-b4de-a914aa796d80
Feed Name: CloudSEK Blog
Threat Score
This report describes a WebView vulnerability in Android apps where a deep-link handling Activity can be abused to load attacker-controlled pages into an app WebView along with authorization headers, allowing remote theft of authentication tokens and other sensitive data; the document includes a concrete exploit example (manifest and Activity code) and recommended mitigations such as validating link origins and sanitizing externally supplied JavaScript.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
