software-mobile
Audited by Socket on Sep 23, 2026
2 alerts found:
Anomalyx2The fragment appears to be a legitimate WebView application template with no clear malicious payload. It contains meaningful security weaknesses: a hardcoded session cookie, permissive third-party cookies and CSP, unvalidated deep-link and push data, unsafe JavaScript interpolation, and ineffective SSL-pinning guidance. These issues warrant remediation before production use, but the visible code does not indicate intentional malware or data exfiltration.
No clear malicious or intentionally harmful behavior is present in the visible fragment. The principal security issue is enabling HttpLoggingInterceptor at BODY level in the production network client, which can expose passwords, tokens, and API data through logs. Use NONE in production or restrict logging to a sanitized, debug-only configuration. The assessment is limited to the supplied partial file.