<div class="csl-bib-body">
<div class="csl-entry">Beer, P., Roth, S., Lindorfer, M., & Squarcina, M. (2026). Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at Scale. In <i>Proceedings of the 35th USENIX Security Symposium</i> (pp. 2685–2704). https://doi.org/10.34726/12683</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/230804
-
dc.identifier.uri
https://doi.org/10.34726/12683
-
dc.description.abstract
While the widespread adoption of HTTPS and browser-based visual warnings for HTTP content has largely mitigated machine-in-the-middle (MitM) attacks on the traditional Web, the mobile ecosystem presents a different situation. Web content embedded via the Android WebView component commonly lacks these built-in visual security indicators and grants apps granular control over transport-layer security. This flexibility raises a critical question: does the mobile-Web ecosystem keep up with the advancements of the modern Web?
In this paper, we perform the first large-scale analysis of HTTP inclusion in WebViews across 189,779 Google Play apps. Despite Android's default policy of blocking HTTP traffic, we find that 33.74% of apps explicitly opt out. Dynamic analysis of 35,000 apps reveals that 69.96% of apps that opt out also relax the Mixed Content Policy, and we observe active HTTP traffic in 2,790. The security impact of these configurations is severe. We identify high-profile apps with 10M+ installations vulnerable to attacks ranging from phishing to full app takeover. Furthermore, we identify a major ad library transmitting cleartext ads, exposing billions of users to MitM attacks. We conclude with a qualitative developer study revealing that insecure practices are frequently driven by the requirements of third-party ad libraries and misconceptions regarding WebView's security configuration modes.
en
dc.description.sponsorship
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds
-
dc.description.sponsorship
FWF - Österr. Wissenschaftsfonds
-
dc.language.iso
en
-
dc.rights.uri
http://creativecommons.org/licenses/by-nd/4.0/
-
dc.subject
mobile application security
en
dc.subject
Android WebView
en
dc.subject
HTTP
en
dc.subject
HTTPS
en
dc.subject
mixed content
en
dc.subject
cleartext traffic
en
dc.subject
transport-layer security
en
dc.subject
machine-in-the-middle attacks
en
dc.subject
static and dynamic app analysis
en
dc.title
Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at Scale
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.rights.license
Creative Commons Namensnennung - Keine Bearbeitungen 4.0 International
de
dc.rights.license
Creative Commons Attribution-NoDerivatives 4.0 International
en
dc.identifier.doi
10.34726/12683
-
dc.contributor.affiliation
University of Bayreuth, Germany
-
dc.relation.isbn
978-1-939133-58-8
-
dc.description.startpage
2685
-
dc.description.endpage
2704
-
dc.relation.grantno
ICT22-060
-
dc.relation.grantno
F 8500
-
dc.type.category
Full-Paper Contribution
-
tuw.booktitle
Proceedings of the 35th USENIX Security Symposium
-
tuw.peerreviewed
true
-
tuw.project.title
Fixing the Broken Bridge Between Mobile Apps and the Web
-
tuw.project.title
Semantische und kryptografische Grundlagen von Informationssicherheit und Datenschutz durch modulares Design