logo

WeChat devs introduced security flaws when they modded TLS, say researchers

ID: 93e558c9-45ab-58cc-a8de-b2a1b4f6d180

STIX ID: report--93e558c9-45ab-58cc-a8de-b2a1b4f6d180

Feed Name: The Register (Security)

Threat Score
20/100

Date Published: 2024-10-17

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Citizen Lab analyzed WeChat's custom MMTLS and its legacy AES-CBC business-layer encryption, finding implementation weaknesses — deterministic IVs, lack of forward secrecy, AES-CBC vulnerabilities and plaintext metadata leakage (user IDs, request URIs). Although these issues deviate from standard TLS and could expose metadata internally, MMTLS currently envelopes the business-layer ciphertext and researchers found no evidence of known exploitable attacks; Tencent is reportedly migrating business-layer encryption toward AES-GCM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.