Urgent.News

What's breaking now, across thousands of outlets.

Science

WeChat worm could pwn a friend before they even answered the call

Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down

WeChat worm could pwn a friend before they even answered the call

A zero-click vulnerability in WeChat's VoIP stack, dubbed WeWorm, has been discovered by researchers at Calif. This flaw, which affects both iOS and Android devices, allows a trusted contact to take control of a user's account simply by calling them, even before the recipient answers the call. The compromised account can then call other contacts and repeat the process without user interaction.

Once exploited, the attacker can read and send messages, make calls, and act on behalf of the victim. Although Tencent has pushed fixes to address the attack, the researchers behind WeWorm are withholding key details. The vulnerability could potentially be chained with other Android and iOS bugs to compromise an entire device. The researchers argue that the exploit highlights the potential scale and severity of cyber threats as AI increases the capabilities of threat actors.

Brief written by urgent.news from The Register Science's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theregister.com →

More in Science

More from Wednesday 9 September →