微信漏洞
code ·
Disclosure timeline Sometime in July, 2026: Our AI discovered the bug. July 23: Our engineering team became aware of the bug. July 24: We submitted the bug to Tencent. July 25-28: Our WeChat accounts were banned. July 29: Our WeChat accounts were unbanned. July 30: We completed the first Android RCE exploit. August 2: We completed the iOS RCE exploit. August 11: We completed the polished worm demo across Android and iOS. August 21: Tencent published Android 8.0.77 and iOS 8.0.76 that mitigated the bug. August 26: Tencent notified us that they're assessing the issue. August 28: We confirmed that our exploit was mitigated on the server side for all users. September 3: We shared our technical analysis and working exploits with Tencent. September 4: Tencent confirmed that the vulnerability could be exploited for remote command execution. September 8: We published this article alongside coverage from The New York Times. September 11: The New York Times published a follow-up analysis of WeWorm and its implications for China. 具体在以下links https://calif.io/research/weworm https://archive.is/arHsF