Sergey Toshin, a security researcher at Positive Technologies, has found a vulnerability that existed in all versions of Android starting with version 4.4. It was discovered to be a bug in WebView, which could be used to install malware or direct applications to access users' personal data, authentication tokens and headers , and other sensitive data
The bug was classified as “high” critical by Google when the appropriate security patch (CVE-2019-5765) was released.
The bug was found in Chromium which uses WebView in Android versions 4.4 and later. , WebView allows web pages to be displayed in Android apps. This potentially affected Chromium-based mobile browsers such as Google Chrome, Samsung Internet Browser, and Yandex Browser.

The bug was fixed in the latest Google Chrome 72, but users using Android are advised to check if they have benefited from the critical update.
Leigh-Anne Galloway, Cyber Security Resilience Lead at Positive Technologies said: “Since Android 7.0, WebView has been implemented via Google Chrome and therefore updating the browser is sufficient to fix the bug. In previous Android versions, WebView must be updated via Google Play. Users who do not have Google Play on their smartphones will need to wait for a WebView update from the device manufacturer.”
