The manifest file is usually the first thing that a penetration tester will check on an engagement. It contains a declaration of a minimum level of API which application requires and a minimum Android version required to run the program. An attacker can access the application data by assuming the privileges of that application or can run arbitrary code under that application permission. In the case of non-debuggable application, an attacker would first need to root the device to extract any data. We will use insecurebank.apk application to demonstrate. We recommend you to take the best Android Hacking and Penetration Testing Course.”]
Source: https://gbhackers.com/android-application-penetration-testing-part-4/

