The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.