Overview
- Calif disclosed Tuesday that its researchers built a proof-of-concept worm called WeWorm that exploited a memory-corruption bug in WeChat’s VoIP stack to take over accounts from an incoming call without any user interaction.
- The worm hijacks a compromised account and uses that account’s saved contacts to place calls that can infect other devices, and Calif demonstrated cross-platform spread between Android and iPhone test phones.
- Calif reported the flaw to Tencent in July, Tencent released Android 8.0.77 and iOS 8.0.76 on 21 August, and Calif says a server-side block confirmed on 28 August mitigated the exploit for all users.
- There are no public reports of the flaw being used in the wild, but Calif is withholding technical details and indicators until a conference presentation, so defenders cannot reliably search for past compromises now.
- Calif says AI tools helped speed discovery and exploit development, a point researchers raise to warn that similar zero-click capabilities may become easier for less-skilled attackers and should prompt industry and government cooperation on AI-related security.