Zero-click worm spreads on iPhones and Android via WeChat calls

Zero-click worm spreads on iPhones and Android via WeChat calls
View on original source
Category: SciTech
Share
Archive
Like
A zero-click worm can spread between iPhones and Android devices through WeChat calls, allowing attackers to hijack accounts even without victims answering. Dubbed WeWorm, the proof-of-concept attack exploits a memory corruption vulnerability in WeChat's Voice-over-IP (VoIP) stack. Calif reported the flaw to Tencent in July, and the company has since deployed mitigations that the researchers say block the exploit for all users. Calif says its researchers discovered the vulnerability with the help of AI and developed the first remote code execution (RCE) exploit in roughly two days. The team completed an Android exploit on July 30, an iOS version on August 2, and a polished cross-platform worm demonstration by August 11. WeChat is Tencent's messaging and social platform and is deeply embedded in everyday communications and services in China, while also being widely used by Chinese communities worldwide. With a user base exceeding one billion accounts, a remotely exploitable flaw in its calling infrastructure could give attackers an unusually large target population. To demonstrate the attack, Calif used three phones: two Pixel 10a Android devices and an iPhone 17e. The first Android phone called the iPhone, exploited WeChat while the device was still ringing, and gained control of the victim's account. The compromised iPhone then automatically became the next attacker and called the second Android phone, compromising it in the same way. The victim does not need to answer the incoming call. Calif says exploitation completes within seconds and can provide control over the WeChat account, including the ability to read and send messages, place calls, and impersonate the victim. Answering the malicious call does not prevent exploitation, while declining it interrupts that particular attempt. However, an attacker could retry later. The exploit does have one important limitation: the calling account must already be on the victim's WeChat friend list. Calif argues this would not necessarily stop worm-like propagation because an attacker could first compromise an existing contact and then use that trusted account to target additional people. By itself, the demonstrated bug compromises WeChat, not the entire device. However, Calif says it can be chained with separate Android or iOS vulnerabilities to potentially achieve broader device control. The underlying flaw is a memory corruption issue in WeChat's VoIP implementation, but Calif is withholding technical details while additional work is underway on similar messaging-app attack surfaces. The researchers plan to disclose the full analysis at a future conference. Tencent released WeChat Android 8.0.77 and iOS 8.0.76 on August 21. Calif subsequently confirmed on August 28 that the exploit had also been mitigated server-side for all users, before sharing its complete analysis and working exploits with Tencent on September 3. If you liked this article, be sure to follow us on X/Twitter and also LinkedIn for more exclusive content.

(0)Comments

 

A note on cookies

Newshunt uses essential cookies to keep you signed in and to remember your language and country, so the site works the way you expect. With your permission, we'd also like to use analytics cookies to understand how people use Newshunt and improve it over time.

Accepting only affects analytics. To learn more, view our Privacy Policy or Terms & Conditions.