logo

WeChat and Instant Messaging Apps Exposed to Various Attack Vectors, New Research Shows

ID: 8cd134e7-7587-5086-83ec-3cb464bf8605

STIX ID: report--8cd134e7-7587-5086-83ec-3cb464bf8605

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-05-30

Date Updated: 2026-05-05

Author: Mayura

...
...

Security researchers (DARKNAVY) disclose critical client-side vulnerabilities in popular instant messaging clients — including WeChat, DingTalk, and QQ — where maliciously crafted files and abused custom protocol handling can lead to remote code execution and full device compromise without user interaction; the report links libwebp CVEs (CVE-2023-41064, CVE-2023-4863), compares the risk to prior zero-click iMessage exploits, highlights mini-program permission and embedded browser risks, and recommends patching, sandboxing, strict validation, and cautious handling of untrusted files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.