Researchers Demonstrate Call‑Based WeChat Worm That Bypasses User Interaction
Security researchers have unveiled a proof‑of‑concept worm that can compromise a WeChat account simply by receiving an inbound call, even if the recipient never answers or interacts with the device. The exploit, demonstrated by a team at a California‑based research group, leverages a flaw in the way the popular messaging app processes call‑related data, allowing the malicious code to execute automatically.
The team built the worm to propagate through the network of contacts stored in a victim's WeChat address book. When the infected user receives a call, the worm triggers a series of actions that hijack the account, granting the attacker access to messages, contacts, and potentially other linked services. Because no user input is required, the attack sidesteps typical user‑awareness defenses that rely on prompting users to avoid suspicious links or files.
Tencent, the Chinese tech giant that owns WeChat, responded quickly after learning of the demonstration. The company issued a patch that blocks the specific exploit vector used by the researchers, effectively neutralizing the worm’s ability to spread via incoming calls. Tencent also advised users to update their apps to the latest version and to remain vigilant for any unusual activity on their accounts.
WeChat, with over a billion monthly active users, is a cornerstone of digital communication in China and among Chinese diaspora communities worldwide. Its integration of messaging, payments, and social features makes it a lucrative target for attackers seeking to harvest personal data or conduct financial fraud. The newly disclosed call‑based worm highlights a previously underexplored attack surface, emphasizing that even seemingly benign phone activities can be weaponized.
Security experts note that the research underscores the importance of rigorous input validation and sandboxing within mobile applications. While the proof‑of‑concept was created in a controlled environment, the methodology could be adapted by malicious actors if the underlying vulnerability were not patched. The incident also raises broader concerns about the security of other popular messaging platforms that handle voice call signaling.
Looking ahead, Tencent has pledged to conduct a comprehensive security audit of WeChat’s codebase and to collaborate with external researchers on responsible disclosure practices. The episode serves as a reminder to users that keeping software up to date remains one of the most effective defenses against emerging threats, and that developers must continually assess how seemingly innocuous features, such as incoming calls, might be exploited.
Comments (0)
Be the first to comment.
Join the discussion