Share

WeChat exposed to Apple malware risk

Hong Kong - Tencent Holdings fixed a flaw in its WeChat instant messaging application that exposed some of the service’s 600 million users to malicious software when downloading the software from Apple, according to a post on its website.

The malware, named XcodeGhost, secretly collects information on devices and uploads the data to servers without users knowing, according to cybersecurity company Palo Alto Networks.

Apps were infected after software developers used compromised versions of Apple’s developer tool kit, the researcher said in a report posted on its website.

A total of 39 apps using Apple’s iOS software - including WeChat and that from ride-hailing service Didi Kuaidi - were infected, potentially affecting hundreds of millions of users, Palo Alto Networks said.

The malware is capable of prompting fake alerts to phish for user credentials, infect other apps using iOS and read users’ passwords.

“We believe XcodeGhost is a very harmful and dangerous malware that has bypassed Apple’s code review and made unprecedented attacks on the iOS ecosystem,” Palo Alto Networks said in the report.

“The techniques used in this attack could be adopted by criminal and espionage focused groups to gain access to iOS devices.”

Didi Upgrade

XcodeGhost already has conducted phishing attacks that prompt dialogue boxes asking victims to input passwords to Apple’s iCloud, the report said.

Tencent said the flaw only affected WeChat version 6.2.5 for iOS, and new versions of 6.2.6 or later won’t be affected. Based on a preliminary investigation, the malware hasn’t caused any theft of users’ information from WeChat, Tencent said.

Didi Kuaidi said the malware potentially could transmit the app name, installation time, language and country settings of its Didi Chuxing version 4.0 app, though users’ privacy wasn’t affected. The issue was addressed in updated version 4.1, the company said in an e-mail.

The security breach previously was reported by the Wall Street Journal.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.09
-0.4%
Rand - Pound
23.79
-0.4%
Rand - Euro
20.35
-0.3%
Rand - Aus dollar
12.29
-0.4%
Rand - Yen
0.12
-0.3%
Platinum
949.00
-0.4%
Palladium
1,045.50
+1.0%
Gold
2,382.28
+0.9%
Silver
28.46
+0.9%
Brent Crude
87.29
-3.1%
Top 40
67,117
+0.3%
All Share
73,184
+0.3%
Resource 10
63,211
-0.3%
Industrial 25
98,180
+0.4%
Financial 15
15,491
+0.7%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders