การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Application Security

Zero-Click WeChat VoIP Flaw Allowed Remote Code Execution

FORTSECURE GLOBAL· 2026-09-10🛰 The Register - Security
#Vulnerability#Application Security#Mobile Security#Network Security
Zero-Click WeChat VoIP Flaw Allowed Remote Code Execution

Researchers revealed a critical zero-click vulnerability in WeChat's VoIP module capable of delivering worms and executing arbitrary code before calls were answered.

The Impact of Zero-Click Memory Corruption

Cybersecurity researchers have detailed a critical remote code execution (RCE) vulnerability discovered in WeChat's VoIP handling library. The flaw was zero-click, meaning an attacker could compromise a targeted device simply by initiating a voice call, without requiring the recipient to accept the connection.

Investigations revealed that artificial intelligence-assisted fuzzing techniques played a pivotal role in discovering and engineering the exploit from a subtle memory corruption flaw into a weaponized, cross-platform RCE chain. Tencent resolved the vulnerability following responsible disclosure, avoiding wide-scale exploitation in the wild.

Practical Recommendations for Mitigating Zero-Click Threats

Zero-click vectors represent one of the most perilous classes of cyber threats due to the lack of necessary user interaction. Key mitigation strategies include:

  • Promptly Update Mobile and Desktop Clients: Ensure all communication applications across managed fleets are immediately updated to the latest supported releases.
  • Enforce Mobile Threat Defense (MTD): Integrate MTD solutions within Enterprise Mobility Management (EMM) platforms to spot signs of memory tampering and payload delivery.
  • Network Level Inspection: Monitor outbound network connections from client endpoints for anomalous communications following unexpected VoIP or media signaling.

แหล่งที่มา: The Register - Security เผยแพร่ครั้งแรก: Wed, 09 Sep 2026 14:45:00 +0200 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: The Register - Security

เผยแพร่ครั้งแรก: Wed, 09 Sep 2026 14:45:00 +0200

บทความต้นฉบับ: https://www.theregister.com/security/2026/09/09/wechat-worm-could-pwn-a-friend-before-they-even-answered-the-call/5295234

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog