balazsgerlei / SecureWebView

Android WebView wrapper with secure defaults to avoid security issues caused by misconfiguring WebViews.
Creative Commons Zero v1.0 Universal
6 stars 3 forks source link

💎 Copilot and Gemini chat should be disallowed/blocked #1

Closed patrik1katai closed 4 months ago

patrik1katai commented 5 months ago

Was able to breakout of the Secure WebView sample app by navigating through to Copilot on Microsoft, or to Gemini on Google. From there (after logging in) on Copilot I was able to reach other search engines like Brave. On Gemini links are redacted from chat, but there is still a Google button that searches on Google and lets you open suggestion links to the search results page.

I think these AI chats should be added to the disallowed list and maybe some other popular ones that could be reachable through socials.

balazsgerlei commented 5 months ago

I can look it up, but even for confirmation can you write down the URLs for the AI chatbots you've encountered? Thanks!

patrik1katai commented 5 months ago

Here are the URLs for the ones I could reach: https://gemini.google.com/ https://copilot.microsoft.com/