How does the app read the variable if it can't be read after you input it? Or do they mean you can't view it after providing the variable value to the UI?
But that's just a bare-minimum defense-in-depth. The fact that an attacker was able to access the insecure variables, and likely the names of secure variables, is still horrifying.
It’s not like I had a ton of trust in them before, but now they’ve lost almost all credibility.