Researchers Uncover WeChat Vulnerability
Security experts from Calif have identified a significant vulnerability in WeChat, enabling attackers to hijack accounts through an incoming call, without user interaction. The flaw, demonstrated on test devices, was reported to Tencent in July, leading to a swift mitigation.
How the Zero-Click Exploit Works
The exploit operates by leveraging a zero-click mechanism, where the target need not interact with their phone. The attacker, however, must already be a contact of the target on WeChat. This flaw mirrors past vulnerabilities, such as the one patched by WhatsApp last year, which also involved zero-click exploits.
Spread and Mitigation of the Worm
During tests, an Android device exploited an iPhone by calling it, and the compromised device then infected another Android phone similarly. Although no real-world attacks have been reported, the potential for misuse was significant, prompting Tencent to block the exploit through server-side fixes.
WeChat’s Broad Impact and Update
WeChat, with over 1.4 billion active users, extends beyond messaging, encompassing payments and mini-programs. Tencent’s updates to versions 8.0.77 for Android and 8.0.76 for iOS included crucial patches. However, no formal advisory was issued, and details on affected versions remain undisclosed.
Future Security Measures and Research
Calif plans to unveil detailed findings at an upcoming conference, holding back technical specifics to prevent exploitation. The research highlights the role of AI in identifying and exploiting such vulnerabilities, emphasizing the need for continuous vigilance and timely updates.
