WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.
What happened
WeChat is a “super-app”, allegedly used by roughly 1. 4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.
Where the sources line up
Security researchers from Calif have now disclosed finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference. ” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app.
Practical impact for readers
In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.
Who should pay attention now
The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device). The next step is to see whether the current signals harden into a durable change or fade as a short-lived experiment. That is why the useful reading move is not to stop at the headline, but to compare the promise, the workflow change, and the likely cost before deciding anything.
What is still unclear
A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call Android users beware — if you own one of these budget smartphones, your device could be hacked with a simple video call New WhatsApp phishing campaign allows for remote access from a single business document Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening.
Latest comments
0No comments yet. You can start the conversation.