A critical, self-propagating security flaw in WeChat allows a zero-click attack to compromise accounts on both iOS and Android devices simply through an incoming call. Demonstrated by security researchers, the worm poses a severe risk to the platform's billion-plus users and demands immediate precautionary measures from individuals and organizations.
Researchers at security firm CaliSec revealed they built and successfully demonstrated a worm that hijacks WeChat accounts without any interaction from the target. The attack is triggered by an incoming call from an attacker who is already in the victim's contact list; answering or touching the phone is not required. In a controlled test, the worm automatically spread, compromising five phones in sequence.
The exploit's identical functionality across Apple's iOS and Google's Android platforms confirms the vulnerability lies within WeChat's own code, not the underlying mobile operating systems. This places remediation responsibility squarely on Tencent, WeChat's parent company. CaliSec reported the flaw in August, and Tencent has acknowledged it, but has not yet issued a public patch or timeline.
The combination of a zero-click entry point and worm-like, self-replicating behavior represents a significant escalation in mobile threats. Once activated, the worm leverages the compromised account to attempt further infections within its contact network, creating the potential for a rapid, automated chain reaction.
This is particularly alarming given WeChat's role as an indispensable super-app for messaging, payments, and business coordination in many regions. A self-spreading worm within this ecosystem could lead to widespread account takeovers, enabling financial fraud, corporate espionage, and the theft of sensitive communications from both individuals and enterprises.
In the absence of a verified patch from Tencent, security experts and IT administrators should treat this as a high-priority incident. Organizations are strongly advised to issue internal alerts, mandate immediate application updates once a patch is released, and consider restricting sensitive communications on WeChat until a confirmed fix is deployed. The incident highlights the growing sophistication of attacks targeting essential communication infrastructure and underscores the need for robust security practices in complex super-app platforms.
微信平台存在一個嚴重的自我傳播安全漏洞,允許攻擊者透過一通來電即可進行零點點擊攻擊,在iOS及Android裝置上入侵用戶帳戶。安全研究人員展示的蠕蟲漏洞對該平台逾十億用戶構成嚴重威脅,個人及機構亟需採取預防措施。
安全公司CaliSec研究團隊透露,他們成功研發並實證了一種無需目標用戶互動即可劫持微信帳戶的蠕蟲程式。攻擊由已在受害者聯絡人名單中的攻擊者發起來電觸發,無需接聽或觸碰手機。在受控測試中,該蠕蟲自動擴散,依次入侵了五部手機。
該漏洞在蘋果iOS與Google Android平台上展現完全相同的功能,證實缺陷源於微信自身代碼而非底層流動作業系統。這意味著補救責任完全落在微信母公司騰訊身上。CaliSec於八月通報此漏洞,騰訊已確認但尚未發布公開補丁或修復時間表。
零點點擊入口結合蠕蟲式自我複製行為,代表流動威脅的重大升級。漏洞一旦激活,蠕蟲將利用被入侵的帳戶嘗試在其聯絡網絡內進一步擴散感染,引發快速自動化的連鎖反應。
鑒於微信在眾多地區作為不可或缺的超級應用程式,用於通訊、支付及業務協調的角色,此情況尤為令人擔憂。該生態系統中的自我傳播蠕蟲可能導致大規模帳戶入侵,助長金融詐騙、企業間諜活動,並竊取個人及企業的敏感通訊。
在騰訊發布經核實的補丁之前,安全專家及IT管理員應將此視為高優先級事故。強烈建議機構發出內部警報,補丁發布後立即強制更新應用程式,並在確認修復部署前限制透過微信進行敏感通訊。此事件突顯針對基礎通訊設施攻擊日益複雜化的趨勢,並強調了複雜超級應用平台對強健安全實踐的需求。
