Enabling JavaScript together with file access on a WebView can allow local file exfiltration by malicious scripts.
Disable file access for WebViews that render remote content and only enable JavaScript when strictly required.