WeChat Faces an Epic-Scale Security Flaw: Simply Making a Voice Call Could Compromise Your Account
2 hour ago / Read about 0 minute
Author:小编   

Recently, the security research organization Calif Research unveiled a zero-click attack demonstration, dubbed "WeWorm". This alarming exploit allows attackers to hijack a WeChat account merely by initiating a voice call, with no need for the victim to answer, click on any link, or input a password. The account can be hijacked even during the ringing phase. Once compromised, the account will autonomously initiate calls to other contacts, propagating the threat in a chain reaction across both Android and iOS platforms. This vulnerability originates from a memory corruption issue within WeChat's VoIP protocol stack. Attackers can exploit this flaw to gain complete control over the account, enabling them to access chat histories, send messages, and make calls. Tencent has promptly addressed this security gap in Android version 8.0.77 and iOS version 8.0.76, and has also implemented server-side safeguards. Presently, users who have upgraded to the latest version are no longer susceptible to this threat.