Particle.news

WeChat Zero-Click Worm Demonstrated and Reported, Tencent Says It Has Blocked the Exploit

Claimed server-side blocking plus app updates aim to stop the worm, leaving defenders without searchable indicators.

Overview

  • Calif disclosed Tuesday that its researchers built a proof-of-concept worm called WeWorm that exploited a memory-corruption bug in WeChat’s VoIP stack to take over accounts from an incoming call without any user interaction.
  • The worm hijacks a compromised account and uses that account’s saved contacts to place calls that can infect other devices, and Calif demonstrated cross-platform spread between Android and iPhone test phones.
  • Calif reported the flaw to Tencent in July, Tencent released Android 8.0.77 and iOS 8.0.76 on 21 August, and Calif says a server-side block confirmed on 28 August mitigated the exploit for all users.
  • There are no public reports of the flaw being used in the wild, but Calif is withholding technical details and indicators until a conference presentation, so defenders cannot reliably search for past compromises now.
  • Calif says AI tools helped speed discovery and exploit development, a point researchers raise to warn that similar zero-click capabilities may become easier for less-skilled attackers and should prompt industry and government cooperation on AI-related security.