payu-intrepos / Android-Custom-Browser

Custom Browser module for SDK
11 stars 9 forks source link

Vulnerable to JavaScript interface injection #14

Closed GouravdeepSingh closed 5 years ago

GouravdeepSingh commented 5 years ago

Hi, i am using custom-browser version 7.2.2 in Android app. Today, i find following security alert on google play console:

Security alert

Your app includes a WebView that is vulnerable to JavaScript interface injection. Please see this Google Help Center article for details.

Vulnerable locations: com.payu.custombrowser.c->L Please fix the issue before: 02/13/2019

According to alert, there is webview security issue in custom-browser. please check this issue as soon as possible.

pavanjaju commented 5 years ago

I am also having this issue, I am also not sure whether they will remove the app or it just a deadline. Solve it asap.

himgupta229 commented 5 years ago

Hi, We have updated CustomBrowser to version 7.3.0 and Option#2 is now implemented.

himgupta229 commented 5 years ago

Closing issue as there has been no update.