Zero-Click WeChat Worm Hijacks Accounts Through Incoming Calls

1 min read
Source: thehackernews.com
Zero-Click WeChat Worm Hijacks Accounts Through Incoming Calls
Photo: thehackernews.com
TL;DR Summary

Researchers from Calif demonstrated a zero-click worm that hijacks a WeChat account via an incoming call from a trusted contact, without the user answering. Once the exploit runs, the attacker can read and send messages, make calls, and act as the account owner, though only the account and not the device is compromised. Tencent patched the bug with Android/iOS updates and blocked the exploit on its servers; no real-world attacks have been reported. The attack relies on the caller being in the contact list, and full technical details will be released later.

Share this article

Reading Insights

Total Reads

1

Unique Readers

8

Time Saved

4 min

vs 5 min read

Condensed

89%

80892 words

Want the full story? Read the original article

Read on thehackernews.com