diff --git a/docs/html/guide/topics/manifest/provider-element.jd b/docs/html/guide/topics/manifest/provider-element.jd index c80b20742cc28..bee87e6933447 100644 --- a/docs/html/guide/topics/manifest/provider-element.jd +++ b/docs/html/guide/topics/manifest/provider-element.jd @@ -96,10 +96,19 @@ If "{@code false}", the provider is available only to components of the same application or applications with the same user ID. The default value is "{@code true}". -
-You can export a content provider but still limit access to it with the
-permission attribute.
-
You can export a content provider but still limit access to it with the
+permission
+attribute. Note that due to a bug in versions of Android prior to {@link
+android.os.Build.VERSION_CODES#VERSION_GINGERBREAD} providers were exported
+even if {@code android:exported} were set to {@code false}. Therefore, for
+provider security on all devices, protect your provider with a
+signature-level permission. For information on defining a permission, see
+the permission
+element. For information on using the permission, see the uses-permission
+element.