The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modify messages and a friends list via a crafted application.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.