WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
Security
WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
Tencent has patched up a zero-click vulnerability that security researchers used to create a worm capable of spreading through calls on WeChat.
With more than 1.4 billion monthly active users, WeChat is among the most popular apps in the world. According to researchers at Calif, its VoIP stack contained a memory corruption bug that could enable a trusted contact to take control of a user's account simply by calling them.
Calif called the flaw WeWorm, describing it as the first zero-click worm capable of spreading through WeChat calls on both iOS and Android.
Calif released a demo of the vulnerability in action this week, and although Tencent has pushed fixes to address the attack on August 21, the team that found it is still withholding key details.
In Calif's demonstration, the exploit took control of a victim's WeChat account within seconds, without the recipient answering the call. The compromised account then called another contact and repeated the process without user interaction.
Declining the call stopped infection, but answering it or allowing it to continue ringing did not. An attacker could also try again when the recipient was away from the phone, the researchers said.
"Exploitation takes only seconds, and gives us full control of the WeChat account," Calif said. "We can read and send messages, make calls, and act on the victim's behalf."
The exploit requires the attacker to be on the victim's friends list. Calif argued that this offered limited protection because a compromised account could be used to target its trusted contacts.
Calif said the WeWorm exploit could be chained with other vulnerabilities to compromise an entire device rather than only a WeChat account. It did not disclose the full attack chain.
"Chained with other Android and iOS bugs we've reported and are helping fix, it can lead to full control of the device," the researchers said.
"[Attackers] could exploit another app, gain root access using techniques like those in OEMpocalypse, take over the victim's WeChat app, and use it to attack you."
Calif said it used AI to find the vulnerability and develop its first remote code execution (RCE) exploit in about two days. Tencent later confirmed the researchers' findings.
The researchers said they published their high-level findings to highlight how AI could make such capabilities available beyond "well-funded, sophisticated actors."
Calif plans to present the full analysis of WeWorm "at an upcoming conference."
Ryan Fedasiuk, an adjunct assistant professor in Georgetown University's Security Studies Program, described the discovery of WeWorm as "an extremely serious incident."
He called on the US and China to maintain open communication and share information as AI increases the potential scale and severity of cyber threats.
The Register asked Tencent for additional comment. ®
Originally published on The Register


