diff --git a/java/ql/src/Security/CWE/CWE-200/AndroidWebViewSettingsFileAccess.qhelp b/java/ql/src/Security/CWE/CWE-200/AndroidWebViewSettingsFileAccess.qhelp index f80c9f9a05d..fa4b1e1696f 100644 --- a/java/ql/src/Security/CWE/CWE-200/AndroidWebViewSettingsFileAccess.qhelp +++ b/java/ql/src/Security/CWE/CWE-200/AndroidWebViewSettingsFileAccess.qhelp @@ -21,6 +21,11 @@
setAllowFileAccessFromFileURLssetAllowUniversalAccessFromFileURLsIf your application requires access to the file system, it is best to
+ avoid using file:// urls, and instead use an alternative that
+ allows loading files via https, such
+ as androidx.webkit.WebViewAssetLoader.