WebView hijacking (via deeplink)
Via un domain takeover
private boolean isAuthorisedURL(String url)
{
String [] allowedHosts = {"example.com", "test.com", "staging.site"};
for(String str: allowedHosts)
if (url.equals(str))
return true;
return false;
}Via contournement de validation de l'URL
Absence de validation du schéma
Ressources
Mis à jour