Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls

https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-2121-80.jpg
  • Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls
  • “WeWorm” spreads through ringing calls; victims need not answer to be compromised
  • Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild

Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.

WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more