Skip to content

Add MASTG-TECH-0142 for inspecting Android WebView storage#3605

Open
SuyashJain17 wants to merge 1 commit intoOWASP:masterfrom
SuyashJain17:mastg-tech-0142-webview-storage
Open

Add MASTG-TECH-0142 for inspecting Android WebView storage#3605
SuyashJain17 wants to merge 1 commit intoOWASP:masterfrom
SuyashJain17:mastg-tech-0142-webview-storage

Conversation

@SuyashJain17
Copy link

@SuyashJain17 SuyashJain17 commented Dec 27, 2025

This PR closes #3602

Description

Adds MASTG-TECH-0142 to document direct inspection of Android WebView
storage under /data/data/<app_package>/app_webview/ using adb,
@MASTG-TOOL-0006, and Android Studio.

Note: The issue references MASTG-TEST-0320 as an example. This test does not
currently exist, and existing MASVS-PLATFORM tests were reviewed without
finding a suitable location for a reference. This change therefore
focuses on adding the missing technique.


AI Tool Disclosure

Check exactly one option.

  • This contribution does not include AI-generated content.
  • This contribution includes AI-generated content.

If AI tools were used to generate or substantially modify code or text, complete the following.

  • AI tools used: e.g. ChatGPT, GitHub Copilot, Claude.
  • Models and versions: e.g. GPT-, Claude .
  • Prompt summary: brief description of the key prompts or instructions.
  • Your mobile security expertise level: low, medium, high.

For first-time contributors using AI tools.

  • Provide an export of the AI chat or session, for example a shared link or PDF attachment.
  • Ensure the commit history shows an initial commit with AI-generated content followed by commits that demonstrate review, correction, and improvement.

Undisclosed use of AI tools will result in the PR being closed. Large rewrites or bulk changes generated by AI require explicit prior approval from the maintainers. Learn more in "Use of AI tools in contributions".


Contributor Checklist

  • I have read and understood the contributing guidelines.
  • I followed the project style guide.
  • I validated the technical correctness of my changes and understand the topic.
  • This PR adds clear value and is not spam or low-effort content.

Relevant documentation.

Contributors are expected to understand basic git and GitHub workflows, including forks, branches, commits, and pull requests. The project does not provide training. Pull requests that do not meet these minimum requirements may be closed without review.

@OWASP OWASP deleted a comment Dec 30, 2025
@OWASP OWASP deleted a comment Dec 30, 2025
@OWASP OWASP deleted a comment Dec 30, 2025
@OWASP OWASP deleted a comment Dec 30, 2025
Copy link
Collaborator

@cpholguera cpholguera left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please also update the declarations in the PR description: #3605

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Please resolve the conflicts, the goal was to update the existing TECH, not to create a new one.
  • The mentioned test does exist and should be accordingly updated: https://mas.owasp.org/MASTG/tests/android/MASVS-PLATFORM/MASTG-TEST-0320/
  • Please do not break lines as you're doing. Each paragraph should be a line.
  • No need to justify why the technique is needed or what the best practices are.
  • Use @MASTG-TOOL-XXXX IDs everywhere.
  • If another MASTG-TECH covers part of the steps here you should use it instead (e.g. for "Obtain a shell").
  • Refer to MASTG-KNOW-0018 for "what to expect within this folder".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update and use MASTG-TECH-0142

2 participants