CVE-2021-40180: Infoleak
Published Jul 26, 2022
·Updated
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
Affected Software
2 affected components
Tencent Wechat Android=8.0.10
Tencent Wechat Iphone Os=8.0.10
Event History
Jul 26, 2022
CVE Published
via MITRE·10:36 PM
Data Sourced
via MITRE·10:36 PM
Description
Frequently Asked Questions
1
What is CVE-2021-40180?
CVE-2021-40180 is a vulnerability in the WeChat application 8.0.10 for Android and iOS.
2
How does CVE-2021-40180 work?
CVE-2021-40180 allows a mini program to obtain sensitive information from a user's address book via wx.searchContacts.
3
What is the severity of CVE-2021-40180?
CVE-2021-40180 has a severity rating of 7.5 (high).
4
Which software versions are affected by CVE-2021-40180?
The WeChat application version 8.0.10 for Android and iOS is affected by CVE-2021-40180.
5
How can I fix CVE-2021-40180?
To fix CVE-2021-40180, update your WeChat application to the latest version available.