| Title: | Vulnerability in MobileQQ (手机QQ) for Android | 
	| Time: | 29 Dec 2011 | 
	| Author: | Daoyuan Wu*, Xiapu Luo* and Rocky K. C. Chang | 
	|  | Department of Computing, The Hong Kong Polytechnic University, Hong Kong | 
	|  | * authors with equal contributions | 
	| CVE ID: | CVE-2011-4864 | 
	| Category: | Newly Released | 
	| Related Vendor: | Tencent, Inc. | 
	| Archive Time: | December 29, 2011 at 2:51 PM HKT | 
	| Package Name: | com.tencent.mobileqq | 
	| Full Name: | MobileQQ ("手机QQ" in Chinese name) | 
	| Affected Version: | 2.2 (the latest version in 29 Dec 2011) | 
	| Package Installs: | 100,000 - 500,000 | 
	| Market Link: | https://market.android.com/details?id=com.tencent.mobileqq | 
	| Status: | Breif impact description now releases to public. | 
	| Breif Description: | Allow a malicious application to access and manipulate user’s private information (e.g., QQ account, friends, messages, and etc.) protected by MobileQQ. | 
	| Contact Time: | Dec 31, 2011 at 2:37 PM HKT | 
	| Confirm Time: | Dec 31, 2011 at 6:08 PM HKT | 
	| Patched Time: | January 12, 2012 HKT | 
	| Patched Status: | Has patched the vulnerability in version 2.3. | 
Although we only mention one or several affected version in our report, other versions may also be vulnerable, e.g. lower version, pad version or paid version.