A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.
No PoCs from references.
- https://github.com/BCsl/WebViewCompat
- https://github.com/heimashi/CompatWebView