Mobile Webview

Exploit insecure mobile WebViews — JS-bridge abuse, file access, and XSS→native. Load when an app renders web content in a WebView/WKWebView, exposes a JS bridge, or loads attacker-influenced URLs. Signals: addJavascriptInterface, WKScriptMessageHandler, loadUrl, file:// access, deep-link → WebView.

NoorQureshi 85253f8 2.2 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/mobile/mobile-webview commit 85253f8b17

Frequently asked questions

npx skillmds@latest add noorqureshi/mobile-webview