Skip to content

Subject: Security Finding — addJavascriptInterface in SDK WebView #352

Description

@RajagopiSurineni

The addJavascriptInterface(oVar, "CleverTap") was identified by our security Team via static decompiled APK analysis using jadx. It does not appear in static build artifact grep, suggesting it may be conditionally registered at runtime during in-app notification rendering. Please confirm whether this interface is registered dynamically and what scope of native methods it exposes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions