Intercepting Android WebView traffic under new certificate validity requirement by Chromium

In a recent security assessment, we were unable to intercept the traffic originating from a WebView from an Android application. The application wasn’t using certificate pinning, nor was it configured in any special way that would prevent normal interception. When testing that same application on a different device, the traffic could be intercepted directly, confirming…

Something went wrong. Please refresh the page and/or try again.