logo

Vulnerability in Tencent WeChat custom browser could lead to remote code execution

ID: 81aa1d1e-7e79-5de5-80e7-2ed5aeabdac8

STIX ID: report--81aa1d1e-7e79-5de5-80e7-2ed5aeabdac8

Feed Name: Cisco Talos

Threat Score
80/100

Date Published: 2024-09-06

Date Updated: 2026-04-27

Author: Ashley Shen

...
...

Cisco Talos discovered that WeChat's custom XWalk WebView included an outdated V8 engine vulnerable to a type-confusion flaw (CVE-2023-3420) that can be exploited via a one-click URL in a message to achieve remote code execution; Talos observed exploitation in the wild, reported the issue to Tencent on April 30, 2024, and notes that affected WeChat versions (up to 8.0.42) and the dynamically loaded XWalk component should be updated immediately (CVSSv3 8.8).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.