WRITEUP · MOBILE · RCE · 2026 · @YNSMROZTAS

Bridge on the wrong origin

● liveclk --:--:--module · B33

A Java object was injected into every document the WebView loaded. The document was not the app.

bridge // liveobserve
radar--:--:--
AndroScopeRCE classWebViewlab only

The trick

addJavascriptInterface puts a Java object on window. That is fine for a file you ship. It is RCE-shaped when the same WebView later loads a URL you do not pin: redirect, open redirect in a help center, file:// from a grant, or a deeplink that sets the document.

Lab app lab.sample.app registered Android on the portal WebView. The activity also accepted an extra that became loadUrl. Same family as Google-app WebView notes: interface lives longer than the origin you meant.

WebView one process @JavascriptInterface Java methods document not allowlisted gap interface attached before origin is known. loadUrl extra later.
B  APP ATTACK SURFACE
33  WebView bridge deep-dive        ★

session — lab.sample.app
[wv] addJavascriptInterface name=Android
[wv] loadUrl from activity extra
[wv] no host allowlist on that WebView
[wv] method list not printed here

mitsec@lab.sample.app:

What AndroScope is allowed to say

Module 33 lists the interface name and whether the document URL is attacker-influenced. It does not print Java method signatures or a JS snippet. If a method reaches files, intents, or eval-shaped APIs, write that as impact class — not as a call sequence.

Class: privileged bridge + unpinned document. That is in-app RCE when the object can start code or write storage. No interface dump on this page.

Fix

YUNUS EMRE ÖZTAŞ · MITSEC · LAB BUILD ONLY