Zero‑Click Worm Exploits WeChat Call Function to Hijack iPhone and Android Accounts
What Happened — Researchers at Calif disclosed a zero‑click worm that can seize a WeChat account simply by receiving an incoming call from a trusted contact. The exploit works on both iOS and Android devices without any user interaction. Tencent was notified in July and has reportedly begun remediation.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of unpatched critical application flaws that can bypass traditional user‑centric defenses.
- Highlights the need for continuous vulnerability‑management controls that capture, prioritize, and remediate zero‑day findings across third‑party software.
- Provides a concrete example of why organizations must maintain auditable evidence of timely patching to satisfy multiple compliance regimes.
Who Is Affected
- Consumers and enterprises that rely on WeChat for communication (messaging, payments, and mini‑programs).
Recommended Actions
- Map this incident to your vulnerability‑management control objective and verify that you have a process for rapid triage of critical third‑party flaws.
- Collect and retain evidence of patch status and remediation timelines to support audit readiness.
- Monitor vendor advisories and apply updates as soon as they are released; consider compensating controls (e.g., network‑level call‑blocking for untrusted numbers) until patches are deployed.
Technical Notes – The worm leverages a flaw in the WeChat call‑handling stack that triggers code execution on receipt of a SIP‑style call payload. No CVE identifier has been published yet, but the vulnerability is classified as a remote code execution with a zero‑interaction requirement, effectively a “zero‑click” exploit. Source: The Hacker News