Key Facts

Calif published a demonstration of WeWorm, a zero-click worm that it says can take over WeChat accounts through incoming calls on iOS and Android. Calif says it demonstrated propagation across three test phones.

Technical Details

Calif describes a memory-corruption flaw in WeChat’s VoIP stack and says the victim need not answer the call. The firm says it is withholding technical details and that the attack requires the caller to be in the victim’s friend list.

Impact & Mitigation

Calif says Tencent mitigated its exploit for all users after coordinated disclosure, and its timeline lists Android 8.0.77 and iOS 8.0.76 as releases that mitigated the bug. No in-the-wild attacks are reported in Calif’s disclosure.

Sources

By Allan