Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls


  • Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls
  • “WeWorm” spreads through ringing calls; victims need not answer to be compromised
  • Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild

Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices – but what makes this flaw stand out is the fact that it’s a zero-click bug – victims need not do a thing to be compromised.

WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.

Source link

spot_img
spot_img

Leave a reply

Please enter your comment!
Please enter your name here