WeChat worm could pwn a friend before they even answered the call

https://image.theregister.com/249321.jpg?imageId=249321&x=0&y=0&cropw=100&croph=71.67&panox=0&panoy=0&panow=100&panoh=71.67&width=1200&height=683

Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down

Tencent has patched up a zero-click vulnerability that security researchers used to create a worm capable of spreading through calls on WeChat.

With more than 1.4 billion monthly active users, WeChat is among the most popular apps in the world. According to researchers at Calif, its VoIP stack contained a memory corruption bug that could enable a trusted contact to take control of a user's account simply by calling them.

Calif called the flaw WeWorm, describing it as the first zero-click worm capable of spreading through WeChat calls on both iOS and Android.

Calif released a demo of the vulnerability in action this week, and although Tencent has pushed fixes to address the attack on August 21, the team that found it is still withholding key details.

In Calif's demonstration, the exploit took...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE

Read more