{"id":17066,"date":"2021-09-17T15:27:32","date_gmt":"2021-09-17T09:57:32","guid":{"rendered":"https:\/\/www.varutra.com\/?p=17066"},"modified":"2022-12-02T12:12:15","modified_gmt":"2022-12-02T06:42:15","slug":"all-you-need-to-know-about-android-webview-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/","title":{"rendered":"All you need to know about Android WebView Vulnerabilities"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities-1024x535.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"All you need to know about Android WebView Vulnerabilities - Varutra Consulting\"><br \/>\nIn this blog we are going to understand about Android WebView Vulnerabilities.<\/p>\n<h3>What is WebView ?<\/h3>\n<p>The WebView class in android allows you to load remote URLs and display the web page as a part of the activity layout. It does not work like a full-fledged browser, but it shows data on a web page inside the activity.<\/p>\n<p>For example, you might have seen it when we open links on social media apps like Twitter or Instagram, and the links open ups within the context of the application, but not as a separate browser.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17070 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/WebView.png\" alt=\"What is WebView\" width=\"295\" height=\"525\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/WebView.png 295w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/WebView-169x300.png 169w\" sizes=\"(max-width: 295px) 100vw, 295px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 1.0 Webview<\/p>\n<h3><strong>Pre-requisites:<\/strong><\/h3>\n<ol>\n<li>ADB &#8211; Android Debug Bridge<\/li>\n<li>JADX \u2013 Android Decompiler<\/li>\n<li>Android Emulator<\/li>\n<\/ol>\n<p>For the testing purpose, we are using a vulnerable android application called\u00a0<a href=\"https:\/\/github.com\/t4kemyh4nd\/vulnwebview\">Vulnerable WebView Application<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17071 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Vulnerable-WebView-App.png\" alt=\"Android WebView Vulnerabilities App\" width=\"369\" height=\"504\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Vulnerable-WebView-App.png 369w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Vulnerable-WebView-App-220x300.png 220w\" sizes=\"(max-width: 369px) 100vw, 369px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 2.0 Vulnerable WebView App<\/p>\n<p>In the below screenshot we can see that the application is loading the bugcrowd page in WebView.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17072 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/bugcrowd-page-in-WebView.png\" alt=\"bugcrowd page in WebView\" width=\"379\" height=\"551\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/bugcrowd-page-in-WebView.png 379w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/bugcrowd-page-in-WebView-206x300.png 206w\" sizes=\"(max-width: 379px) 100vw, 379px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 3.0 bugcrowd page in WebView<\/p>\n<p>&nbsp;<\/p>\n<h3>How to look for WebView Vulnerabilities in Application?<\/h3>\n<p>WebViews are a part of the activities of the android application. We first need to decompile the app and go through the application\u2019s activities to check for any vulnerability. We will use the JADX tool to decompile the application. Once the application is decompiled, we will look at the android manifest file to get an overview of the structure of the application and its components. To find the vulnerable WebView we will look at the exported components of the android application.<\/p>\n<p>The application has some components that are exported. The MainActivity is exported via intent filters whereas the SupportWebView and RegistrationWebView are explicitly exported.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17073 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/SupportWebView.png\" alt=\"Support WebView\" width=\"608\" height=\"193\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/SupportWebView.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/SupportWebView-300x95.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 4.0<\/p>\n<p>Go to the Registration WebView activity, and see that webview and its client have been imported into the activity. At the bottom, you can see that webview has been used.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17074 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/RegistrationWebView.png\" alt=\"Registration Web View\" width=\"608\" height=\"286\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/RegistrationWebView.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/RegistrationWebView-300x141.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 5.0<\/p>\n<p>To spot the vulnerability, you see the code is loading the URL, and it is using a string sent through the intent to load the URL. The third-party applications can be easily exploited by this behavior as intent can be easily sent to the component with a URL string attached to it. Then, the target application will accept this because the component is exported. i.e., third-party applications have access to it.<\/p>\n<h3><\/h3>\n<h3>Exploitation of WebView Vulnerabilities:<\/h3>\n<p>For the exploitation, an emulator is used on which the vulnerable application is installed. Now, ADB will be sending an intent to the component. A malicious webpage will be open inside the context of the application. This intent is provided by the attacker.<\/p>\n<p>adb shell am start -n component name &#8211;es string &#8220;example.com&#8221;<\/p>\n<p>ADB shell starts a unique shell on a device. AM stands for activity manager, and android is instructing that it is to manage all the components in the application start.<\/p>\n<ul>\n<li>-n is used for the name of the component,<\/li>\n<li>&#8211;es stands for extra string<\/li>\n<li>here extra is \u201creg_url\u201d.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17075 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Exploitation.png\" alt=\"Exploitation\" width=\"608\" height=\"58\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Exploitation.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Exploitation-300x29.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 6.0<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17077 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/evil.png\" alt=\"Evil Registration Page\" width=\"396\" height=\"642\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/evil.png 396w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/evil-185x300.png 185w\" sizes=\"(max-width: 396px) 100vw, 396px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 7.0<\/p>\n<p>In the above screenshot, you can see that intent is sent, and it has opened up evil.com within the context of the vulnerable application. So, this is how we can exploit a vulnerable exported activity that contained a WebView object.<\/p>\n<p>It is just a simple scenario to show that how the bugs work. But there are many ways to escalate it. For example,<\/p>\n<ul>\n<li>If the application leaks the authorization token while requesting the attacker-controlled domain, then it may be possible to escalate the vulnerable WebView to full-account takeover.<\/li>\n<li>Another scenario could be, if the application requests a URL using HTTP, then it may also be possible to leak some sensitive token.<\/li>\n<\/ul>\n<h3>set Allow Universal Access From File URLs enabled for a WebView<\/h3>\n<p>Another setting through which a developer can configure is by running JavaScript with the context of file scheme URL to access content from any origin, including other file scheme URLs \u201csetAllowUniversalAccessFromFileURLs\u201d which are enabled for WebView. This setting will remove all same-origin policy restrictions &amp; allows to make requests to the web from the file, which is normally impossible. It means that the attacker can read local files using JavaScript and send them across the web to an attacker-controlled domain. This type of behavior can be dangerous as the component is exported and it will enable the attacker to read arbitrary files which are supposed to be private to the application.<\/p>\n<p>&nbsp;<\/p>\n<h3>Exploitation: set Allow Universal Access From File URLs enabled for a WebView<\/h3>\n<p>We can exploit this vulnerability through the same activity, i.e., Registration WebView. In fig 5.0, you can see that the set Allow Universal Access From File URLs setting is set to true.<\/p>\n<p>To exploit this vulnerability, create an exploit code in JavaScript which is stored in the SD card of the device.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17079 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Universal-Access-From-File-URLs-setting-is-set-to-true.png\" alt=\"Universal Access From File URLs setting is set to true\" width=\"608\" height=\"226\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Universal-Access-From-File-URLs-setting-is-set-to-true.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Universal-Access-From-File-URLs-setting-is-set-to-true-300x112.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 8.0<\/p>\n<p>In the code, a variable is declared, including the file path and the shared preference directory of the application. It contains a .xml file with the login credentials for the application. There is a function called load which will upload the file path and create a request. Once the request is loaded, it will make another request to the burp collaborator link. Another parameter is added, i.e., \u201cexfiltrated\u201d and the value of that parameter will be from the response that was created earlier from the file. Now, we are calling the load function to load the file URL.<\/p>\n<p>To send the intent ADB command is used. Here the URL is the path to the exploit code which is present in the SD card.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17080 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/ADB-command.png\" alt=\"ADB command\" width=\"608\" height=\"69\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/ADB-command.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/ADB-command-300x34.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 9.0<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17076 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Registration-page.png\" alt=\"Registration page\" width=\"369\" height=\"566\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Registration-page.png 369w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Registration-page-196x300.png 196w\" sizes=\"(max-width: 369px) 100vw, 369px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 10.0<\/p>\n<p>In the image above, the intent has opened up the registration page, and a request in the burp collaborator with base64 encoded value is visible.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17081 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Decode-the-base64-value-in-the-decoder.png\" alt=\"Decode the base64 value in the decoder\" width=\"608\" height=\"338\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Decode-the-base64-value-in-the-decoder.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Decode-the-base64-value-in-the-decoder-300x167.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 11.0<\/p>\n<p>Decode the base64 value in the decoder.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17082 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/disclosing-personal-credentials.png\" alt=\"disclosing personal credentials\" width=\"608\" height=\"179\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/disclosing-personal-credentials.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/disclosing-personal-credentials-300x88.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 12.0<\/p>\n<p>In the figure above, the content of the file is loaded, disclosing personal credentials.<\/p>\n<p>&nbsp;<\/p>\n<h3>JavaScript enabled for a WebView Vulnerabilities:<\/h3>\n<p>Another feature of WebView is that it supports the use of JavaScript. It can be enabled in WebViews by adding this configuration webView.getSettings().setJavaScriptEnabled(true). This setting will create an interface between the webpage\u2019s JavaScript and the client-side java code of the application. i.e., the web page\u2019s JavaScript can access and inject java code into the application.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17083 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/SupportWebView-activity-has-enabled-the-support-of-JavaScript.png\" alt=\"SupportWebView activity has enabled the support of JavaScript\" width=\"608\" height=\"246\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/SupportWebView-activity-has-enabled-the-support-of-JavaScript.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/SupportWebView-activity-has-enabled-the-support-of-JavaScript-300x121.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 13.0<\/p>\n<p>In the above figure, the SupportWebView activity has enabled the support of JavaScript in the code. You can also go into the android declaration from the web app interface and look where the JavaScript interface is declared.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17084 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/14.png\" alt=\"14\" width=\"608\" height=\"318\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/14.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/14-300x157.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 14.0<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17085 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/WebView-is-also-loading-the-URL-through-support_url..png\" alt=\"WebView is also loading the URL through support_url.\" width=\"560\" height=\"280\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/WebView-is-also-loading-the-URL-through-support_url..png 560w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/WebView-is-also-loading-the-URL-through-support_url.-300x150.png 300w\" sizes=\"(max-width: 560px) 100vw, 560px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 15.0<\/p>\n<p>From the code, you can see that WebView is also loading the URL through support_url.<\/p>\n<p>&nbsp;<\/p>\n<h3>Exploitation of WebView Vulnerabilities:<\/h3>\n<p>For this vulnerability exploitation, you can use the exploit code that is hosted on the python server. In the screenshot below, you can see the simple JavaScript code in which the token is mentioned. It is then requesting for the get user method from the android object and android id. The name of the interface and get user token gets the value of the authorization token.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17086 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/vulnerability-exploitation.png\" alt=\"vulnerability exploitation\" width=\"550\" height=\"190\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/vulnerability-exploitation.png 550w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/vulnerability-exploitation-300x104.png 300w\" sizes=\"(max-width: 550px) 100vw, 550px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 16.0<\/p>\n<p>To exploit this vulnerability, use the ADB command. The command will be the same except for the activity name and extra string.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17087 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/17.png\" alt=\"17\" width=\"607\" height=\"38\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/17.png 607w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/17-300x19.png 300w\" sizes=\"(max-width: 607px) 100vw, 607px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 17.0<\/p>\n<p>&nbsp;<\/p>\n<p>After sending the intent, you can see that the support page is open in the application, and it is disclosing the token value.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17088 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/support-page.png\" alt=\"support page\" width=\"286\" height=\"527\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/support-page.png 286w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/support-page-163x300.png 163w\" sizes=\"(max-width: 286px) 100vw, 286px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 18.0<\/p>\n<p>You can also use this vulnerability to perform XSS by changing, \u201cdocument.write\u201d in the previously used exploit code to any XSS payload.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17090 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/XSS-by-changing.png\" alt=\"XSS by changing\" width=\"512\" height=\"188\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/XSS-by-changing.png 512w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/XSS-by-changing-300x110.png 300w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 19.0<\/p>\n<p>To perform the XSS, execute the same ADB command with the URL containing the JavaScript code with the XSS payload.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17091 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/20.png\" alt=\"20\" width=\"608\" height=\"36\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/20.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/20-300x18.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 20.0<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17092 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/21.png\" alt=\"21\" width=\"329\" height=\"609\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/21.png 329w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/21-162x300.png 162w\" sizes=\"(max-width: 329px) 100vw, 329px\" \/><\/p>\n<p style=\"text-align: center\">Fig: 21.0<\/p>\n<p>You can visit our <a href=\"https:\/\/www.varutra.com\/blogs\/\">website<\/a> to know more about our services to prevent those attacks or browse our<a href=\"https:\/\/www.varutra.com\/blogs\/\"> blog<\/a> section to know more about other <a href=\"https:\/\/www.varutra.com\/varutrapreprod\/category\/android-security\/\">Android vulnerabilities.<\/a><\/p>\n<p>&nbsp;<\/p>\n<h3><strong><u>References<\/u><\/strong><\/h3>\n<p><a href=\"https:\/\/github.com\/B3nac\/Android-Reports-and-Resources\">https:\/\/github.com\/B3nac\/Android-Reports-and-Resources<\/a><\/p>\n<p><a href=\"https:\/\/zsecurity.org\/hacking-android-webviews\/\">https:\/\/zsecurity.org\/hacking-android-webviews\/<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<p><strong>Piyush Sonkushre<\/strong><\/p>\n<p>Attack &amp; Pentest Team<\/p>\n<p>Varutra Consulting Pvt. Ltd.<\/p>","protected":false},"excerpt":{"rendered":"<p>In this blog we are going to understand about Android WebView Vulnerabilities. What is WebView ? The WebView class in android allows you to load&#8230;<\/p>\n","protected":false},"author":4,"featured_media":17068,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.7.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"WebViews are used in android applications to load content &amp; HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"kalpblogger\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.7.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"All you need to know about Android WebView Vulnerabilities\" \/>\n\t\t<meta property=\"og:description\" content=\"WebViews are used in android applications to load content &amp; HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t\t<meta property=\"article:section\" content=\"General\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-09-17T09:57:32+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T06:42:15+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"All you need to know about Android WebView Vulnerabilities\" \/>\n\t\t<meta name=\"twitter:description\" content=\"WebViews are used in android applications to load content &amp; HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpblogger\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#article\",\"name\":\"All you need to know about Android WebView Vulnerabilities\",\"headline\":\"All you need to know about Android WebView Vulnerabilities\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png\",\"width\":1200,\"height\":627,\"caption\":\"All you need to know about Android WebView Vulnerabilities\"},\"datePublished\":\"2021-09-17T15:27:32+05:30\",\"dateModified\":\"2022-12-02T12:12:15+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#webpage\"},\"articleSection\":\"General\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/general\\\/#listItem\",\"name\":\"General\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/general\\\/#listItem\",\"position\":2,\"name\":\"General\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/general\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#listItem\",\"name\":\"All you need to know about Android WebView Vulnerabilities\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#listItem\",\"position\":3,\"name\":\"All you need to know about Android WebView Vulnerabilities\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/general\\\/#listItem\",\"name\":\"General\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/\",\"name\":\"kalpblogger\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/\",\"name\":\"All you need to know about Android WebView Vulnerabilities\",\"description\":\"WebViews are used in android applications to load content & HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#mainImage\",\"width\":1200,\"height\":627,\"caption\":\"All you need to know about Android WebView Vulnerabilities\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/all-you-need-to-know-about-android-webview-vulnerabilities\\\/#mainImage\"},\"datePublished\":\"2021-09-17T15:27:32+05:30\",\"dateModified\":\"2022-12-02T12:12:15+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>All you need to know about Android WebView Vulnerabilities<\/title>\n\n","aioseo_head_json":{"title":"All you need to know about Android WebView Vulnerabilities","description":"WebViews are used in android applications to load content & HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#article","name":"All you need to know about Android WebView Vulnerabilities","headline":"All you need to know about Android WebView Vulnerabilities","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png","width":1200,"height":627,"caption":"All you need to know about Android WebView Vulnerabilities"},"datePublished":"2021-09-17T15:27:32+05:30","dateModified":"2022-12-02T12:12:15+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#webpage"},"articleSection":"General"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/general\/#listItem","name":"General"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/general\/#listItem","position":2,"name":"General","item":"https:\/\/www.varutra.com\/varutravrt3\/category\/general\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#listItem","name":"All you need to know about Android WebView Vulnerabilities"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#listItem","position":3,"name":"All you need to know about Android WebView Vulnerabilities","previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/general\/#listItem","name":"General"}}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","description":"Secure your digital world with our Cybersecurity services.","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/","name":"kalpblogger","image":{"@type":"ImageObject","url":"https:\/\/secure.gravatar.com\/avatar\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/","name":"All you need to know about Android WebView Vulnerabilities","description":"WebViews are used in android applications to load content & HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#mainImage","width":1200,"height":627,"caption":"All you need to know about Android WebView Vulnerabilities"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/#mainImage"},"datePublished":"2021-09-17T15:27:32+05:30","dateModified":"2022-12-02T12:12:15+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"All you need to know about Android WebView Vulnerabilities","og:description":"WebViews are used in android applications to load content &amp; HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png","og:image:width":"1200","og:image:height":"627","article:section":"General","article:published_time":"2021-09-17T09:57:32+00:00","article:modified_time":"2022-12-02T06:42:15+00:00","twitter:card":"summary_large_image","twitter:title":"All you need to know about Android WebView Vulnerabilities","twitter:description":"WebViews are used in android applications to load content &amp; HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png","twitter:label1":"Written by","twitter:data1":"kalpblogger","twitter:label2":"Est. reading time","twitter:data2":"6 minutes"},"aioseo_meta_data":{"post_id":"17066","title":"All you need to know about Android WebView Vulnerabilities","description":"WebViews are used in android applications to load content &amp; HTML pages. Understand all about Android WebView Vulnerabilities and Exploitation.","keywords":[],"keyphrases":{"focus":{"keyphrase":"WebView Vulnerabilities","analysis":{"keyphraseInTitle":{"title":"Focus keyphrase in SEO title","description":"Focus keyphrase found in SEO title.","score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"title":"Focus keyphrase in meta description","description":"Focus keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Focus keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":2},"keyphraseInURL":{"title":"Focus keyphrase in URL","description":"Focus keyphrase used in the URL.","score":5,"maxScore":5,"error":0},"keyphraseInIntroduction":{"title":"Focus keyphrase in introduction","description":"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInSubHeadings":{"title":"Focus keyphrase in Subheadings","description":"Your H2 and H3 subheadings reflects the topic of your copy. Good job!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Focus keyphrase in image alt attributes","description":"Focus keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}},"score":90},"additional":[{"keyphrase":"WebView","score":100,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase appears in the first paragraph. Well done!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"Android WebView Vulnerabilities","score":83,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":3},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"Vulnerabilities","score":83,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}}]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/All-you-need-to-know-about-Android-WebView-Vulnerabilities.png","og_image_width":"1200","og_image_height":"627","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"General","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"created":"2021-10-27 15:10:53","updated":"2026-05-24 09:56:49","ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-05-22 12:21:37"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/general\/\" title=\"General\">General<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tAll you need to know about Android WebView Vulnerabilities\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"General","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/general\/"},{"label":"All you need to know about Android WebView Vulnerabilities","link":"https:\/\/www.varutra.com\/varutravrt3\/all-you-need-to-know-about-android-webview-vulnerabilities\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17066"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=17066"}],"version-history":[{"count":5,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17066\/revisions"}],"predecessor-version":[{"id":20263,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17066\/revisions\/20263"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/17068"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=17066"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=17066"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=17066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}