Tuesday, 02 January 2024 12:17 GMT

Researchers Disclose Wechat Zero-Click Call Worm Arabian Post


(MENAFN- The Arabian Post) clearfix">Security researchers have disclosed a zero-click worm capable of hijacking WeChat accounts through incoming calls on both iPhones and Android phones, although the exploit has been mitigated before public release.

California-based security firm Calif said its WeWorm demonstration exploited a memory-corruption flaw in WeChat's voice-over-IP stack, allowing a compromised account to call another user and seize control of that account within seconds without the target answering or touching the phone.

The researchers said Tencent, which operates WeChat, had mitigated the exploit for all users by the time the findings were published on September 8. Calif said Android version 8.0.77 and iOS version 8.0.76, issued on August 21, addressed the weakness, while a server-side measure confirmed on August 28 blocked the exploit across the service.

MENAFN09092026000152002308ID1111643109



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story