

And it gets even stranger. Apparently, the app is loading JavaScript from a random person’s GitHub site for YouTube embeds. Yes, you read that right, it’s just loading JavaScript from a random GitHub site. So if that account ever gets compromised, arbitrary code could run inside the app’s WebView.
Somebody has the opportunity to do the most hilarious thing.



Him? Keep gifts that almost certainly contain spy equipment? He’d never do that. Certainly not giant, 747 sized ones.