WeChat Zero-Click Worm Exploits Incoming Calls
Security researchers have demonstrated a critical zero-click vulnerability in WeChat that allows attackers to take over user accounts through incoming calls, even if the recipient does not answer. The worm, dubbed WeWorm, can then propagate to other contacts. Tencent, the app's parent company, has since released patches and implemented server-side mitigations. The exploit, developed by researchers at Calif, requires the attacker to already be a WeChat contact of the target. However, researchers noted this is a low barrier, as compromising one account can grant access to its contacts. The worm can spread between Android and iOS devices. The vulnerability lies within WeChat's Voice over Internet Protocol (VoIP) stack, involving a memory corruption issue. When an incoming call rings, the worm exploits this flaw to gain control of the WeChat account. Successful exploitation grants attackers full control of the compromised WeChat account, enabling them to read and send messages, and make calls. Researchers emphasized that the vulnerability, on its own, does not grant control of the entire smartphone, but could potentially be chained with other device-specific flaws.