AI Security AI安全 3h ago Updated 1h ago 更新于 1小时前 46

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls 微信零点击蠕虫通过来电劫持iPhone和Android账户

A zero-click worm developed by Calif security researchers can take over WeChat accounts via an incoming call without any action from the target The exploit works on both iPhone and Android, requiring only that the caller be on the target's WeChat contact list Once compromised, the attacker gains full account control including reading/sending messages, making calls, and acting as the account owner Tencent mitigated the vulnerability server-side by August 28, 2026, though no CVE or public advisory Calif安全公司发现微信零点击蠕虫漏洞,可通过来电劫持iPhone和Android微信账号,无需用户接听或操作手机 攻击者只需是受害者微信联系人列表中的一员即可实施攻击,一旦账号被劫持可获得完全控制权(读取/发送消息、拨打电话等) 腾讯已在8月21日发布更新(Android 8.0.77、iOS 8.0.76)修复该漏洞,并在服务器端阻止了利用,无需用户手动更新 研究人员利用AI辅助在约两天内发现漏洞并编写首个exploit,整个蠕虫开发周期约一周 该漏洞未分配CVE编号,腾讯也未发布安全公告,技术细节被保密将在会议上公布

72
Hot 热度
65
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • A zero-click worm developed by Calif security researchers can take over WeChat accounts via an incoming call without any action from the target
  • The exploit works on both iPhone and Android, requiring only that the caller be on the target's WeChat contact list
  • Once compromised, the attacker gains full account control including reading/sending messages, making calls, and acting as the account owner
  • Tencent mitigated the vulnerability server-side by August 28, 2026, though no CVE or public advisory was published
  • AI was used to discover the bug and write the initial exploit in approximately two days, with the full worm demo completed within three weeks

Why It Matters

This represents a significant escalation in zero-click attack capabilities against messaging platforms with integrated financial services, affecting 1.439 billion users. The contact-list trust model exploitation demonstrates how social graph relationships can be weaponized for lateral movement, while the server-side mitigation approach highlights both the effectiveness and opacity of vendor security responses.

Technical Details

  • Attack vector: Incoming WeChat voice/video call triggers exploit code execution without target interaction; answering the call also fails to prevent exploitation
  • Trust model abuse: Once a contact is compromised, the elevated trust WeChat grants to contacts becomes an attack multiplier for lateral propagation
  • Account takeover scope: Full account control achieved (messages, calls, account actions) without device-level compromise
  • AI-accelerated discovery: Calif reported using AI to identify the vulnerability and develop the initial exploit in approximately two days
  • Server-side mitigation: Tencent blocked the exploit on their servers by August 28, 2026, without requiring client updates

Industry Insight

  • The contact-trust exploitation model should be re-evaluated across messaging platforms; social graph relationships should not automatically confer elevated privileges without additional verification
  • Server-side vulnerability blocking demonstrates an effective mitigation strategy for zero-click flaws, but the lack of CVE assignment and transparent advisory undermines defensive security practices
  • AI-accelerated exploit development (2 days to initial exploit) signals a new baseline for vulnerability discovery timelines that security teams must account for in threat modeling and patch prioritization

TL;DR

  • Calif安全公司发现微信零点击蠕虫漏洞,可通过来电劫持iPhone和Android微信账号,无需用户接听或操作手机
  • 攻击者只需是受害者微信联系人列表中的一员即可实施攻击,一旦账号被劫持可获得完全控制权(读取/发送消息、拨打电话等)
  • 腾讯已在8月21日发布更新(Android 8.0.77、iOS 8.0.76)修复该漏洞,并在服务器端阻止了利用,无需用户手动更新
  • 研究人员利用AI辅助在约两天内发现漏洞并编写首个exploit,整个蠕虫开发周期约一周
  • 该漏洞未分配CVE编号,腾讯也未发布安全公告,技术细节被保密将在会议上公布

为什么值得看

本文展示了AI在安全漏洞发现中的实际应用价值,研究人员利用AI辅助大幅缩短了漏洞挖掘和exploit编写周期。同时揭示了即时通讯平台社交信任机制被滥用的新型攻击向量,对移动安全研究具有重要参考意义。

技术解析

  • 漏洞利用链:攻击者通过微信来电触发零点击exploit,在对方接听前即可劫持账号;接听电话后用户听不到任何声音,但exploit仍在运行;挂断电话可终止当次尝试,但攻击者可再次拨打
  • AI辅助发现:Calif团队使用AI工具辅助漏洞发现和exploit编写,首次exploit开发约耗时两天,蠕虫构建耗时一周;但内部时间线显示工程团队7月23日知晓漏洞,7月30日完成首个Android exploit,8月11日完成蠕虫演示
  • 蠕虫传播机制:一旦初始账号被劫持,攻击者可以利用微信对联系人的额外信任进行横向移动;演示中Android手机呼叫iPhone劫持账号,随后被劫持的iPhone呼叫第二台Android手机
  • 修复方案:腾讯在服务器端部署了防护机制(8月28日确认生效),无需用户手动更新即可阻止攻击;但具体受影响版本未公开,用户无法自查历史版本是否中招
  • 影响范围:微信月活用户达14.39亿(截至2026年6月30日),漏洞仅劫持账号而非手机本身,但微信整合支付、公众号、小程序等功能,账号控制权等同于用户数字身份

行业启示

  • 即时通讯平台的"联系人信任机制"存在被滥用的风险,安全架构需重新评估社交关系链在身份验证中的权重,考虑引入来电验证或多因素认证
  • AI辅助安全研究正在改变漏洞发现的速度和效率,传统安全团队需要建立AI协同工作流程,同时厂商需加快漏洞响应和披露透明度
  • 厂商在漏洞修复后未发布安全公告、未分配CVE编号的做法损害用户知情权;建议建立更完善的漏洞披露标准,确保用户能够评估自身风险并采取防护措施

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究