Skip to content
theregister·

🚨WeChat VoIP Vulnerability Allows Account Takeover via Call

A simple call can now control your WeChat account

TL;DR

A new zero-click vulnerability in WeChat's VoIP stack allows a trusted contact to take over a user's account by making a call. The flaw affects both iOS and Android, impacting over 1.4 billion users. Patches were released on August 21.

A zero-click vulnerability in WeChat's VoIP stack lets a trusted contact take over a user's account by making a call. The exploit, dubbed WeWorm, works on both iOS and Android and was patched by Tencent on August 21. If you're using WeChat for sensitive communications, this is a big deal. The vulnerability allowed attackers to gain full control within seconds, with declining the call as the only defense. The exploit required the attacker to be on the victim's friends list, but once compromised, the account could be used to target trusted contacts. This highlights the potential of AI in uncovering and exploiting vulnerabilities, making security a top priority for all users.

WeChat VoIP Vulnerability Allows Account Takeover via Call — theregister

Key Points

1

WeWorm vulnerability allows a trusted contact to take over a WeChat account via a phone call

2

Exploit works on both iOS and Android platforms, affecting over 1.4 billion monthly active users

3

Vulnerability was patched by Tencent on August 21, 2023

4

AI was used to find the vulnerability and develop the RCE exploit in about two days

5

The exploit could be chained with other vulnerabilities to compromise an entire device

Why It Matters

If you're using WeChat for sensitive communications, this is a big deal. The vulnerability allows attackers to take over your account via a call from a trusted contact. The patch was released on August 21, but users need to ensure they're up to date to protect their accounts. This highlights the importance of staying vigilant and keeping software updated, especially with the potential for AI to uncover and exploit vulnerabilities.

WeChatVoIPvulnerabilityWeWormAI

Frequently Asked Questions

Why does this matter?

If you're using WeChat for sensitive communications, this is a big deal. The vulnerability allows attackers to take over your account via a call from a trusted contact. The patch was released on August 21, but users need to ensure they're up to date to protect their accounts. This highlights the importance of staying vigilant and keeping software updated, especially with the potential for AI to uncover and exploit vulnerabilities.

What happened?

A new zero-click vulnerability in WeChat's VoIP stack allows a trusted contact to take over a user's account by making a call. The flaw affects both iOS and Android, impacting over 1.4 billion users. Patches were released on August 21.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,472 builders reading daily.

Also get