Experts discover zero-click WeChat worm capable of compromising millions of devices

Security researchers from Calif have identified a critical zero-click vulnerability in WeChat’s VoIP stack, which could allow attackers to take over user accounts via incoming calls. Dubbed "WeWorm," the exploit functions without requiring the victim to answer the call, potentially exposing millions of Android and iOS users to unauthorized access. While the worm could theoretically access messages and contacts, there is no evidence of it being exploited in the wild. Tencent has addressed the vulnerability by deploying server-side mitigations and releasing patches in versions 8.0.77 for Android and 8.0.76 for iOS. The researchers, who plan to present their findings at an upcoming conference, emphasized that this flaw highlights broader security concerns across messaging applications. They are currently investigating similar attack surfaces in other platforms to encourage industry-wide improvements in software security and vulnerability reduction.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
LG Electronics has officially denied allegations that its smart televisions record ambient conversations to facilitate targeted advertising. The state…
A recent analysis of Project Glasswing findings reveals a significant disparity between the volume of discovered vulnerabilities and the actual rate o…
Security researchers at Proofpoint have identified a new exploit kit, dubbed BlueMoon, currently being utilized by at least four distinct hacking grou…



