Skip to content

WeWorm – First zero-click worm to spread through WeChat calls

blog.calif.io
9 pointsquyleanh2 comments
On HN

Comments

“The bug is a memory corruption issue in WeChat's VoIP stack. We're withholding the technical details for now. We plan to present the full analysis at an upcoming conference.

This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps. We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”

Read our story and watch the demos: https://calif.io/research/weworm.
The New York Times also spent time following our work and published their story today: https://archive.is/arHsF
AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.