Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

129
Vistas
PLAY CONSOLE WEB VIEW Cross App Scripting Vulnerability

I'm struggling with my web view App, the google play team said that my app is vulnerable to cross-app scripting. I've tried to enable safe browsing (set it to YES) but the warning from google still appears.

Google recommends setting setJavaScriptEnabled to false, but that's not a valid option for me because I use javascript on my webview app.

Does anybody solve these issues?

about 4 years ago · Juan Pablo Isaza
1 Respuestas
Responde la pregunta

0

Option 1:

Ensure that affected activities are not exported Find any Activities with affected WebViews. If these Activities do not need to take Intents from other apps you can set android:exported=false for the Activities in your Manifest. This ensures that malicious apps cannot send harmful inputs to any WebViews in these activities.

Option 2:

Protect WebViews in exported activities

If you want to set an Activity with an affected WebView as exported then we recommend that you make the following changes:

  1. Protect calls to evaluateJavascript and loadUrl
  2. Prevent unsafe file loads

For more details go to Google Help: Fixing a cross-app scripting vulnerability

about 4 years ago · Juan Pablo Isaza Denunciar
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda