Urgent.News

What's breaking now, across thousands of outlets.

Tech

Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls

Your phone rings, and you're infected - with all of your contacts and messages exposed.

Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls

A team of researchers from California discovered a zero-click vulnerability in the WeChat VoIP system that allows malicious actors to take control of users' accounts on both Android and iOS devices. This flaw, dubbed "WeWorm," takes advantage of a memory corruption issue within the VoIP stack to infiltrate a victim's device simply by making a phone call.

The victim does not need to answer the call for the attack to occur; even a silent ringing call is sufficient for the worm to infect the device. Once inside, the attacker gains access to the victim's WeChat account, including messages, contacts, and other app data. Tencent patched the flaw in Android 8.0.77 and iOS 8.0.76, claiming that the issue has been mitigated on all affected devices.

The researchers chose not to disclose the technical details of the flaw, instead demonstrating it at an upcoming conference. This isn't the first zero-click flaw found in modern smartphones, and it's likely to be the last. Tencent patched the vulnerability, but did not provide further details in their patch notes. The researchers plan to investigate similar flaws in other messaging apps and work with developers to reduce attack surfaces.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Thursday 10 September →