WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Summary
Security researchers have developed a zero-click worm capable of taking over WeChat accounts on both iPhone and Android devices. The worm spreads via incoming calls, requiring no interaction from the victim beyond being a WeChat contact of the attacker. The vulnerability was reported to Tencent in July.
IFF Assessment
This article describes a zero-click worm that can compromise user accounts, representing a significant threat to individual users and their data.
Severity
This worm has a high attack vector (network) and impact (complete account compromise), with low complexity and exploitability, warranting a high CVSS score.
Defender Context
This zero-click worm highlights the critical need for rapid patching and robust endpoint security solutions. Defenders should be aware of advanced attack vectors targeting popular communication applications and emphasize user education on social engineering tactics.