My Android app went through the Quixxi Vulnerability scan and one of the High risk issues was:
Vulnerability : Using Activities/Improper Export of Android Application Activities
Severity : High
Export tag for following activities are not used properly:
com.domain.appname.activities.SplashActivity
In the manifest it looks like this:
<activity
android:name=".activities.SplashActivity"
android:exported="true"
android:theme="@style/SplashTheme">
<intent-filter>
<action android:name="android.intent.action.MAIN" />
<category android:name="android.intent.category.LAUNCHER" />
</intent-filter>
</activity>
When I set android:exported="false" the app doesn't start anymore and Android Studio just shows Client not ready yet...
How can I fix the vulnerability reported by Quixxi?