StandardDraft
CAPEC-503WebView Exposure
Abstraction
Standard
Status
Draft
Description
An adversary, through a malicious web page, accesses application specific functionality by leveraging interfaces registered through WebView's addJavascriptInterface API. Once an interface is registered to WebView through addJavascriptInterface, it becomes global and all pages loaded in the WebView can call this interface.
Related weaknesses· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Access Controlcwe-284 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.