Vulnerability in Tencent WeChat custom browser could lead to remote code execution
ID: 81aa1d1e-7e79-5de5-80e7-2ed5aeabdac8
STIX ID: report--81aa1d1e-7e79-5de5-80e7-2ed5aeabdac8
Feed Name: Cisco Talos
Threat Score
Cisco Talos discovered that WeChat's custom XWalk WebView included an outdated V8 engine vulnerable to a type-confusion flaw (CVE-2023-3420) that can be exploited via a one-click URL in a message to achieve remote code execution; Talos observed exploitation in the wild, reported the issue to Tencent on April 30, 2024, and notes that affected WeChat versions (up to 8.0.42) and the dynamically loaded XWalk component should be updated immediately (CVSSv3 8.8).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
