Researchers disclose WeChat zero-click call worm
Security researchers have disclosed a zero-click worm capable of hijacking WeChat accounts through incoming calls on both iPhones and Android phones, although the exploit has been mitigated before public release. California-based security firm Calif said its WeWorm demonstration exploited a memory-corruption flaw in WeChat’s voice-over-IP stack, allowing a compromised account to call another user…
Security researchers have unveiled a zero-click worm capable of compromising WeChat accounts via incoming calls on both iPhones and Android devices, though the vulnerability has since been rectified. California-based security firm Calif unveiled a demonstration exploiting a memory-corruption flaw in WeChat's voice-over-IP stack, allowing a hijacked account to call another user and seize control within seconds, even without the target's action.
Tencent, WeChat's operator, patched the exploit for all users by September 8. Android version 8.0.77 and iOS version 8.0.76 both addressed the weakness, while a server-side fix on August 28 blocked the exploit across the platform. Calif confirmed on September 8 that the Android exploit was patched on July 30, the iOS fix on August 2, and the cross-platform worm was demonstrated on August 11.
The researchers emphasized that the flaw, while allowing remote code execution within WeChat, required the calling account to be on the target's friend list, though an infected account could still propagate through existing trusted relationships. No evidence suggests the flaw was exploited outside the researchers' controlled tests, and Calif has not claimed it was deployed in the wild.
The company is withholding technical details of the vulnerability pending a full presentation at a security conference.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.