Is it safe to enable JavaScript in Android Web View?

Viewed 158

The majority of my app features are loading in web view. What are the possible security threats if I enable JavaScript, and what are the remedies for them?

My web view code and details are added below.

  • Web view settings.

     this.settings.javaScriptEnabled = true
     this.settings.domStorageEnabled = true
     this.settings.loadWithOverviewMode = true
     this.settings.useWideViewPort = true
     this.settings.cacheMode = WebSettings.LOAD_NO_CACHE
    
  • No HTTP traffic allowed in web view (App running in API 21 and above)

  • No multi window support enabled in web view settings.

  • Not using JavaScript interface.

  • No domain restrictions are added. User can navigate to websites that are not in our control. I know we have to restrict the user to web pages that are under our control as per security best practices. What are the potential threats if I didn't do it?

0 Answers
Related