Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls

Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls | Daily Reports Online

Share


  • Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls
  • “WeWorm” spreads through ringing calls; victims need not answer to be compromised
  • Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild

Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices – but what makes this flaw stand out is the fact that it’s a zero-click bug – victims need not do a thing to be compromised.


WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.


Similar Posts