Empresas
Empregos
  • Sobre nós
  • Soluções
    • Publicação de vagas
      Publique sua vaga e receba candidatos qualificados em 48h.
    • Avaliações de candidatos
      Mais de 500 testes técnicos e psicológicos, mais anti-fraude.
    • Headhunting
      Busca executiva personalizada do início ao fim.
    • Folha de Pagamento + EOR
      Dispersão de folha e EOR em mais de 15 países da LATAM.
  • Preços
  • Empregos

0

135
Visualizações
PLAY CONSOLE WEB VIEW Cross App Scripting Vulnerability

I'm struggling with my web view App, the google play team said that my app is vulnerable to cross-app scripting. I've tried to enable safe browsing (set it to YES) but the warning from google still appears.

Google recommends setting setJavaScriptEnabled to false, but that's not a valid option for me because I use javascript on my webview app.

Does anybody solve these issues?

about 4 years ago · Juan Pablo Isaza
1 Respostas
Responde à pergunta

0

Option 1:

Ensure that affected activities are not exported Find any Activities with affected WebViews. If these Activities do not need to take Intents from other apps you can set android:exported=false for the Activities in your Manifest. This ensures that malicious apps cannot send harmful inputs to any WebViews in these activities.

Option 2:

Protect WebViews in exported activities

If you want to set an Activity with an affected WebView as exported then we recommend that you make the following changes:

  1. Protect calls to evaluateJavascript and loadUrl
  2. Prevent unsafe file loads

For more details go to Google Help: Fixing a cross-app scripting vulnerability

about 4 years ago · Juan Pablo Isaza Relatório
Responde à pergunta
Encontrar trabalhos remotos

Descubra a nova forma de encontrar um emprego!

melhores empregos
Principais categorias de trabalho
Empresas
Postar vaga Preços Comercial
Jurídico
Termos e Condições Política de privacidade
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomende algumas ofertas para mim
Preciso de ajuda