Zero Day Room
Live
Defence

WeChat Zero-Click Worm Hijacks Phones via Calls

Researchers from Calif built a zero-click worm, WeWorm, exploiting a memory corruption flaw in WeChat's VoIP stack.

Defence: Researchers from Calif built a zero-click worm, WeWorm, exploiting a memory corruption flaw in WeChat's VoIP stack

A cybersecurity startup has built a tool that can hack phones through an incoming WeChat call. Researchers from Calif, based in Palo Alto, California, developed the WeWorm hacking tool by exploiting remote code execution vulnerabilities in the Chinese super-app WeChat.

Calif researchers claimed in a September 8 disclosure that this is the first zero-click worm capable of spreading through WeChat calls on both iOS and Android platforms. They tested the tool on devices including Google Pixel 10a models and an iPhone 17e model.

Vulnerability Discovery and Patch

The researchers found the remote code execution bug in WeChat in July. They used a combination of large language models, including open-weight ones and closed-source models from US frontier labs, to aid their discovery. The specific models used were not disclosed.

The flaw is a memory corruption issue within WeChat's voice-over-IP stack. It use the privileges granted to trusted contacts when communicating within the app. The researchers reported the vulnerability to Tencent, WeChat's parent company. Their WeChat account was initially banned following this report.

Tencent later confirmed that exploiting this vulnerability could allow an attacker to perform remote command execution. The company released patched versions of the app: version 8.0.77 for Android and version 8.0.76 for iOS.

How the WeWorm Attack Works

Calif researchers developed exploits for the vulnerable WeChat apps in two days. They then spent an additional week integrating these exploits into the WeWorm tool. WeWorm provides an attacker with full control of a targeted WeChat account upon a successful exploit.

This control allows the attacker to read and send messages, make calls, and act on the victim's behalf. "The victim does not need to answer the call or interact with their phone at all," the researchers wrote. They added that even if a call is answered, the victim hears nothing, and the exploit still succeeds. Declining the call stops an individual attempt, but an attacker can simply try again later.

A key limitation is that the attacker must be on the victim's WeChat friend list. However, the researchers stated this is "not much of a barrier." They explained that an attacker could first compromise one of the victim's friends and use that account as a stepping stone.

Broader Implications and AI's Role

The researchers warned that, when chained with other Android and iOS bugs, WeWorm could lead to full control of the compromised device. They highlighted the accelerated pace of such threat development, attributing it to artificial intelligence.

"A worm at this scale used to be the kind of thing that took a larger team months," the Calif team concluded. "AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely." The disclosure report did not indicate any observed in-the-wild exploitation of these vulnerabilities.

Topics

#Defence

Related coverage

More from Defence