Files
fuzzforge_ai/backend/toolbox/modules/android/custom_rules/webview-javascript-enabled.yaml
2025-10-03 11:45:17 +02:00

17 lines
444 B
YAML

rules:
- id: webview-javascript-enabled
severity: ERROR
languages: [java]
message: "WebView with JavaScript enabled can be dangerous if loading untrusted content."
metadata:
authors:
- Guerric ELOI (FuzzingLabs)
owasp-mobile: M7
category: webview
area: ui
verification-level: [L1]
paths:
include:
- "**/*.java"
pattern: "$W.getSettings().setJavaScriptEnabled(true)"