Interestana
Home/News/WeChat Zero-Click Worm Exploits Incoming Calls on iOS and Android
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

WeChat Zero-Click Worm Exploits Incoming Calls on iOS and Android

WeChat Zero-Click Worm Exploits Incoming Calls on iOS and Android

Security researchers at the firm Calif have developed a sophisticated zero-click worm capable of compromising WeChat accounts on both iOS and Android devices. This worm exploits an incoming call vulnerability, meaning that a user does not need to answer the call or interact with their phone in any way for their account to be taken over. The only prerequisite for the attack is that the malicious caller must already be a contact within the target's WeChat address book. Calif researchers successfully demonstrated the worm's ability to spread autonomously between three test phones, highlighting its potential for widespread exploitation.

The security firm reported this critical flaw to Tencent, the parent company of WeChat, in July. Tencent has since addressed the vulnerability, indicating that patches have been implemented to mitigate the risk. However, the exact timeline for the fix and the specific versions of WeChat affected were not detailed in the initial report. The discovery underscores the persistent threat of zero-click exploits, which are particularly dangerous because they require no action from the victim, making them extremely difficult to detect and prevent.

Zero-click vulnerabilities are highly sought after by malicious actors and intelligence agencies due to their stealth and effectiveness. They bypass traditional security measures that rely on user awareness or interaction, such as clicking on malicious links or opening infected attachments. The ability of this worm to spread via an incoming call, even to contacts, suggests a deep-seated vulnerability within the WeChat application's handling of network communications or call processing. The fact that it affects both major mobile operating systems, iOS and Android, further amplifies the severity of the discovery.

Calif's research team has a history of uncovering significant security vulnerabilities in popular applications. Their work often involves intricate reverse engineering and deep analysis of software protocols. The development of this worm demonstrates a high level of technical expertise and a thorough understanding of how communication applications handle network traffic and incoming signals. The successful demonstration on multiple devices and operating systems provides concrete evidence of the exploit's viability and the potential impact on WeChat's massive user base, which numbers over a billion active users globally. The prompt reporting to Tencent and subsequent patching by the company is a positive outcome, preventing a potentially catastrophic widespread breach.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next