🚨WeChat VoIP Vulnerability Allows Account Takeover via Call
A simple call can now control your WeChat account
TL;DR
A new zero-click vulnerability in WeChat's VoIP stack allows a trusted contact to take over a user's account by making a call. The flaw affects both iOS and Android, impacting over 1.4 billion users. Patches were released on August 21.
A zero-click vulnerability in WeChat's VoIP stack lets a trusted contact take over a user's account by making a call. The exploit, dubbed WeWorm, works on both iOS and Android and was patched by Tencent on August 21. If you're using WeChat for sensitive communications, this is a big deal. The vulnerability allowed attackers to gain full control within seconds, with declining the call as the only defense. The exploit required the attacker to be on the victim's friends list, but once compromised, the account could be used to target trusted contacts. This highlights the potential of AI in uncovering and exploiting vulnerabilities, making security a top priority for all users.

Key Points
WeWorm vulnerability allows a trusted contact to take over a WeChat account via a phone call
Exploit works on both iOS and Android platforms, affecting over 1.4 billion monthly active users
Vulnerability was patched by Tencent on August 21, 2023
AI was used to find the vulnerability and develop the RCE exploit in about two days
The exploit could be chained with other vulnerabilities to compromise an entire device
Why It Matters
If you're using WeChat for sensitive communications, this is a big deal. The vulnerability allows attackers to take over your account via a call from a trusted contact. The patch was released on August 21, but users need to ensure they're up to date to protect their accounts. This highlights the importance of staying vigilant and keeping software updated, especially with the potential for AI to uncover and exploit vulnerabilities.
Frequently Asked Questions
Why does this matter?
If you're using WeChat for sensitive communications, this is a big deal. The vulnerability allows attackers to take over your account via a call from a trusted contact. The patch was released on August 21, but users need to ensure they're up to date to protect their accounts. This highlights the importance of staying vigilant and keeping software updated, especially with the potential for AI to uncover and exploit vulnerabilities.
What happened?
A new zero-click vulnerability in WeChat's VoIP stack allows a trusted contact to take over a user's account by making a call. The flaw affects both iOS and Android, impacting over 1.4 billion users. Patches were released on August 21.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,472 builders reading daily.