High Debug mode enabled

Description

The application is compiled with debug mode allowing attackers to attach a debugger to access sensitive data or perform malicious actions.Attacker can debug the application without access to source code and leverage it to perform malicious actions on behalf ot the user, modify the application behavior or access sensitive data like credentials and session cookies.

Recommendation

Disable debug mode by setting the attribute android:debuggeable to false in the application tag.


    <application android:icon="@drawable/icon" android:debuggable="false">

Technical details
<?xml version="1.0" ?>
<manifest android:compileSdkVersion="28" android:compileSdkVersionCodename="9" android:versionCode="1" android:versionName="1.0" package="com.example.diegosantiago.turbo" platformBuildVersionCode="28" platformBuildVersionName="9" xmlns:android="http://schemas.android.com/apk/res/android">
	

	<uses-sdk android:minSdkVersion="21" android:targetSdkVersion="28">
</uses-sdk>
	

	<uses-permission android:name="android.permission.INTERNET">
</uses-permission>
	

	<uses-permission android:name="android.permission.READ_EXTERNAL_STORAGE">
</uses-permission>
	

	<uses-permission android:name="android.permission.WRITE_EXTERNAL_STORAGE">
</uses-permission>
	

	<uses-permission android:name="com.google.android.providers.gsf.permission.READ_GSERVICES">
</uses-permission>
	

	<uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION">
</uses-permission>
	

	<uses-permission android:name="android.permission.ACCESS_FINE_LOCATION">
</uses-permission>
	

	<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE">
</uses-permission>
	

	<uses-feature android:glEsVersion="0x00020000" android:required="true">
</uses-feature>
	

	<application android:allowBackup="true" android:appComponentFactory="android.support.v4.app.CoreComponentFactory" android:debuggable="true" android:hardwareAccelerated="true" android:icon="@7F0E0000" android:label="@7F0F0028" android:largeHeap="true" android:roundIcon="@7F0E0001" android:supportsRtl="true" android:theme="@7F100008" android:usesCleartextTraffic="true">
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.RentedCar">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.WhichCityAreYou">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.ChooseTurboOrCargo">
</activity>
		

		<meta-data android:name="com.google.android.geo.API_KEY" android:value="@7F0F0027">
</meta-data>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.HorariosActivity">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.UbicacionAuto">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.CrearCuentaIngresarDatos">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.OpenImage">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.ConversacionChat">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.Checkout">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.OpenCar">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.Exitoso_Agregar">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.RegisterCar">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Sliders.Slider_No_Car">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.CrearCuenta" android:windowSoftInputMode="0x00000020">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.IniciarSesion">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.LogIn">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.SplashScreen" android:screenOrientation="1" android:theme="@7F100155">
			

			<intent-filter>
				

				<action android:name="android.intent.action.MAIN">
</action>
				

				<category android:name="android.intent.category.LAUNCHER">
</category>
				

			</intent-filter>
			

		</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Actividades.SessionUser" android:windowSoftInputMode="0x00000030">
</activity>
		

		<activity android:name="com.example.diegosantiago.turbo.Sliders.Slider">
</activity>
		

		<uses-library android:name="org.apache.http.legacy" android:required="false">
</uses-library>
		

		<activity android:exported="false" android:name="com.google.android.gms.common.api.GoogleApiActivity" android:theme="@android:01030010">
</activity>
		

		<meta-data android:name="com.google.android.gms.version" android:value="@7F0A0008">
</meta-data>
		

		<provider android:authorities="com.example.diegosantiago.turbo.com.squareup.picasso" android:exported="false" android:name="com.squareup.picasso.PicassoProvider">
</provider>
		

	</application>
	

</manifest>