Description
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
Problem types
CWE-20 Improper Input Validation
Product status
4.23.4 and below
References
security.oppo.com/...ice_only_key=NOTICE-1955879800426209280