Zero-click WeChat call flaw powered WeWorm account-takeover worm; Tencent patches Android and iOS
Researchers found a zero-click WeChat call flaw behind WeWorm, an account-takeover worm. Tencent patched Android and iOS; no in-the-wild exploitation was seen.
The researchers, from Calif, described the flaw as a memory corruption issue in WeChat's VoIP stack. They withheld technical details and plan to demonstrate the bug at an upcoming conference. In their demonstration, WeWorm takes over target WeChat accounts and spreads through phone calls. An attacker must have the target in their WeChat contacts list, according to TechRadar, and can use either an Android or iOS device to call a victim regardless of the victim's phone model or operating system.
The attack does not require the victim to answer. TechRadar reported that as soon as the phone rings, WeWorm begins working on the victim's device. If the victim answers, they hear silence, but the worm continues. If the victim declines the call, the attack stops, although the attacker can call again, including when the victim is asleep or away from the device. Within seconds, the attacker can gain access to the victim's WeChat account, including messages, contacts, and virtually anything else in the app.
The report said the bug's potential impact is heightened because WeChat is used for money transfers and payments, but WeChat Pay has additional authentication and risk controls designed to prevent unauthorized transactions. WeChat is described as a 'super-app' used by roughly 1.4 billion people and is especially popular in China, where it offers messaging, voice and video calls, social networking, payments, food orders, taxi bookings, and access to government and business services.
Tencent did not list details in its patch notes, saying only that the updates brought 'bug fixes.' In a statement shared with The Hacker News, Tencent said the exploit had been 'mitigated for all users' and that the fix was applied server-side, meaning users need not install anything aside from the patch, according to the report. WeChat also has apps for HarmonyOS, Windows, Mac, and Linux, but Calif did not test those platforms and Tencent did not include them in the patch, TechRadar reported.
The researchers said the WeChat bug is one example of unconventional attack surfaces across many messaging apps. 'This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,' they said, according to TechRadar. 'We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction.' They added that the effort may require industry-wide work because some of it depends on platform owners, and that they would share technical details later.
Editor's Summary
Calif researchers disclosed a zero-click WeChat VoIP flaw that can lead to account takeover and demonstrated it with a worm called WeWorm that spreads through ringing calls without the victim answering. Tencent released patches for Android 8.0.77 and iOS 8.0.76 and said the issue has been mitigated for all users, with no evidence of exploitation in the wild. The researchers plan to publish technical details and are examining similar attack surfaces in other messaging apps.