>It was recently discovered that applications do not even need to have a Javascript Interface in their code to be vulnerable to this attack. This is because a Javascript Interface is implemented core webview code in Android versions before 4.2. Meaning that every single application that loads a webview over cleartext is vulnerable to this attack.
Maybe its because I haven't properly had coffee yet or because I've never used WebView in android but I'm having trouble parsing this. From the small code snippet they provided it shows them enabling javascript and adding an interface. Is this just a general comment for other apps that are working on HTTP or broken HTTPS or does it relate to this exploit?