HackApp vulnerability scanner discovered that application Stickers Smileys for WhatsApp published at the βplayβ market has multiple vulnerabilities.
Files created with these methods could be worldwide readable.
WebView 'setJavaScriptEnabled(true)' could be exploited during cross-site scripting attacks.
Control of WebView context allows to access local files.
Code for 'DexClassLoader' could be tampered.
SD-cards and other external storages have 'worldwide read' policy.
Were do they point?
All items deleted with 'file.delete()' could be recovered.