WeChat zero-click worm hijacks accounts via calls
๐ก๏ธ A Palo Alto startup, Calif, developed a tool called WeWorm that exploits a remote code execution flaw in WeChat's VoIP stack to compromise Android and iOS devices via incoming calls. Researchers say the zero-click exploit required no user interaction and can hijack accounts to read/send messages and make calls. Tencent patched the vulnerability in Android 8.0.77 and iOS 8.0.76 after being notified, and Calif warns the worm could scale further when combined with other bugs.
