Is Android webview in e/OS 4.2 insecure?

Maybe, but unlike 0-day vulnerabilities, virtually anyone can figure out how to design an exploit when a patch for it exists and is freely available, especially with the help of AI. So leaving unpatched critical vulnerabilities becomes even more of an issue nowadays. A similar problem occurs if you keep using your phone long after the end of software support: everyone agrees this is a security risk. How is that different? Of course webview is not android SPL. Personally I’m okay with some delay on android SPL because how you use your phone can possibly mitigate some of the risk (at least I hope so). However we all browse the web and use apps that potentially access the android system webview. There is not much we can do to mitigate this except only using an external up-to-date browser and no apps, especially since many apps do not provide ways to open links in the external browser.

I don’t want to sound too harsh about e/OS. I mean I’ve been running it (and still am) with great joy on my FP6 since over a year now. However I’m looking around at other ROMs (especially since the recent unexpected drop of seedvault in e/OS) and see that others seem to be doing way better with respect to keeping the android webview up to date…

2 Likes