升级至Android SDK 34后出现java.lang.SecurityException问题求助
解决Android SDK 34升级后的java.lang.SecurityException异常
异常原因
Android 14(API 34)强化了广播接收器的安全性规范:所有非系统专属的广播接收器,必须明确指定导出属性——静态注册的接收器需添加android:exported标签,动态注册的接收器需传入RECEIVER_EXPORTED/RECEIVER_NOT_EXPORTED标记。未满足此要求会触发SecurityException。
解决方案
1. 修复静态注册的广播接收器
检查AndroidManifest.xml中所有<receiver>标签,根据接收器用途添加android:exported属性:
- 若接收器需接收其他应用的广播,设为
android:exported="true" - 若仅处理本应用内部广播,设为
android:exported="false"
示例代码:
<receiver android:name=".MyInternalReceiver" android:exported="false"> <intent-filter> <action android:name="com.example.APP_INTERNAL_ACTION" /> </intent-filter> </receiver>
2. 修复动态注册的广播接收器
调用registerReceiver()时,根据系统版本选择适配的API:
- API 33及以上:使用带导出标记的重载方法
- API 32及以下:保留原有注册逻辑
Kotlin示例:
val receiver = MyDynamicReceiver() val filter = IntentFilter("com.example.DYNAMIC_ACTION") if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.TIRAMISU) { registerReceiver(receiver, filter, Context.RECEIVER_NOT_EXPORTED) } else { registerReceiver(receiver, filter) }
Java示例:
MyDynamicReceiver receiver = new MyDynamicReceiver(); IntentFilter filter = new IntentFilter("com.example.DYNAMIC_ACTION"); if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.TIRAMISU) { registerReceiver(receiver, filter, Context.RECEIVER_NOT_EXPORTED); } else { registerReceiver(receiver, filter); }
3. 升级第三方依赖库
你的依赖中存在多个未适配API34的旧版本库,可能内部注册了不符合规范的广播接收器,建议优先升级:
- Glide 3.7.0:升级至
4.16.0及以上(需同步添加Glide注解处理器) - Material组件:移除重复依赖(当前同时引入
1.2.1和1.1.0),升级至1.11.0及以上 - AppCompat:升级至
1.6.1及以上 - ConstraintLayout:升级至
2.1.4及以上 - Volley:升级至
1.2.1及以上
修改后的依赖示例:
dependencies { implementation 'androidx.appcompat:appcompat:1.6.1' implementation 'com.google.android.material:material:1.11.0' implementation 'androidx.constraintlayout:constraintlayout:2.1.4' implementation 'androidx.legacy:legacy-support-v4:1.0.0' testImplementation 'junit:junit:4.13.2' androidTestImplementation 'androidx.test.ext:junit:1.1.5' androidTestImplementation 'androidx.test.espresso:espresso-core:3.5.1' implementation 'com.github.bumptech.glide:glide:4.16.0' annotationProcessor 'com.github.bumptech.glide:compiler:4.16.0' implementation 'me.hiennguyen.circleseekbar:circleseekbar:1.0.1' implementation 'me.itangqi.waveloadingview:library:0.3.5' implementation 'com.github.PhilJay:MPAndroidChart:v3.1.0' implementation "androidx.browser:browser:1.6.0" implementation 'com.github.prolificinteractive:material-calendarview:2.0.1' implementation 'com.shawnlin:number-picker:2.4.11' implementation "org.jetbrains.kotlin:kotlin-stdlib-jdk7:$kotlin_version" implementation 'androidx.multidex:multidex:2.0.0' implementation 'com.google.android.gms:play-services-ads:22.6.0' implementation 'com.onesignal:OneSignal:[4.0.0, 4.99.99]' implementation 'com.android.volley:volley:1.2.1' implementation 'androidx.work:work-runtime-ktx:2.8.1' }
4. 临时覆盖第三方库接收器属性(无法升级时)
若部分库无法升级,可在AndroidManifest.xml中手动覆盖其接收器的android:exported属性,需添加tools:replace="android:exported":
<receiver android:name="com.example.library.LibraryReceiver" android:exported="false" tools:replace="android:exported" />
此方案仅作临时修复,长期建议升级依赖库以避免潜在兼容性问题。
内容的提问来源于stack exchange,提问作者Parmit Singh Malik
相关产品推荐
相关产品推荐

