It has been reported that WeChat harbored a high-risk “zero-click” vulnerability, dubbed WeWorm. Attackers can remotely hijack accounts during the ringing phase by simply initiating a voice call, without requiring any interaction from the user. Once compromised, these accounts will automatically start voice calls to contacts listed in the address book, propagating the issue in a chain-like manner. This vulnerability affects both Android and iOS platforms, with accounts being compromised within seconds of receiving the call. The vulnerability presents a significant threat due to its low barrier to attack, enabling attackers to steal private information and conduct fraud, making it extremely difficult for users to defend against. Currently, WeChat has addressed this vulnerability in the iOS version 8.0.76 and Android version 8.0.77. However, a substantial number of devices that have not been updated remain at risk. This vulnerability was initially identified by an AI security system. Experts note that WeChat’s complex code architecture is susceptible to vulnerabilities. The application of AI technology in the realm of cybersecurity has ushered in an era of rapid, second-level responses in the ongoing attack-defense confrontation. The security community is closely monitoring potential variants of this vulnerability, vigilant against exploitation on the black market to perpetrate fraud chains.
