💻
Critical WeChat flaw: "WeWorm" hijacks accounts without a click
💻 Technology

Critical WeChat flaw: "WeWorm" hijacks accounts without a click

Researchers from California have discovered a zero-click vulnerability in WeChat's VoIP calling feature that allows account takeover on Android and iOS without any user interaction—simply receiving or even making a call is enough. The exploit, named "WeWorm," could spread among WeChat's 1.4 billion users. Tencent patched the flaw in Android 8.0.77 and iOS 8.0.76; no real-world exploitation has been detected so far.

Comments

No comments yet