USENIX Security2026Top-tier venue
Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at Scale
Philipp Beer, Sebastian Roth, Martina Lindorfer, Marco Squarcina
Abstract
While the widespread adoption of HTTPS and browser-based visual warnings for HTTP content has largely mitigated machine-in-the-middle (MitM) attacks on the traditional Web, the mobile ecosystem presents a different situation. Web content embedded via the Android WebView component commonly lacks these built-in visual security indicators and grants apps granular control over transport-layer security. This flexibility raises a critical question: does the mobile-Web ecosystem keep up with the advancements of the modern Web?
In this paper, we perform the first large-scale analysis of HTTP inclusion in WebViews across 189,779 Google Play apps. Despite Android's default policy of blocking HTTP traffic, we find that 33.74% of apps explicitly opt out. Dynamic analysis of 35,000 apps reveals that 69.96% of apps that opt out also relax the Mixed Content Policy, and we observe active HTTP traffic in 2,790. The security impact of these configurations is severe. We identify high-profile apps with 10M+ installations vulnerable to attacks ranging from phishing to full app takeover. Furthermore, we identify a major ad library transmitting cleartext ads, exposing billions of users to MitM attacks. We conclude with a qualitative developer study revealing that insecure practices are frequently driven by the requirements of third-party ad libraries and misconceptions regarding WebView's security configuration modes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 83d05d31-72e0-4a84-b0b9-d30adaa3cba1Builds on19
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 70 citations
- The Rise of the Citizen Developer: Assessing the Security Impact of Online App GeneratorsMarten Oltrogge, Erik Derr, Christian Stransky, Yasemin Acar et al.S&P 2018 · 69 citations
- Time Does Not Heal All Wounds: A Longitudinal Analysis of Security-Mechanism Support in Mobile BrowsersMeng Luo, Pierre Laperdrix, Nima Honarmand, Nick NikiforakisNDSS 2019 · 35 citations
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 32 citations
- 12 Angry Developers - A Qualitative Study on Developers' Struggles with CSPSebastian Roth, Lea Gröber, Michael Backes, Katharina Krombholz et al.CCS 2021 · 22 citations
Related papers
- Towards HTTPS Everywhere on Android: We Are Not There YetAndrea Possemato, Yanick FratantonioUSENIX Security 2020
- Tabbed Out: Subverting the Android Custom Tab Security ModelPhilipp Beer, Marco Squarcina, Lorenzo Veronese, Martina LindorferS&P 2024 · 7 citations
- Cross-Boundary Mobile Tracking: Exploring Java-to-JavaScript Information Diffusion in WebViewsSohom Datta, Michalis Diamantaris, Ahsan Zafar, Junhua Su et al.NDSS 2026 · 2 citations
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- An Empirical Study of Web Resource Manipulation in Real-world Mobile ApplicationsXiaohan Zhang, Yuan Zhang, Qianqian Mo, Hao Xia et al.USENIX Security 2018 · 15 citations
