In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw | permissions required exploit third party advisory |
https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA | permissions required exploit third party advisory |
https://arxiv.org/pdf/2205.15202.pdf | third party advisory technical description mitigation |
https://github.com/BESTICSP/Vulnerabilities-Related-to-Mini-Programs-Permissions/blob/main/WX%20applet%20contact%20permission%20vulnerability%20report.pdf | third party advisory exploit |