Researchers Build Zero-Click Worm That Hijacked WeChat Accounts via a Single Call

Security researchers at the firm Calif built a working worm capable of hijacking WeChat accounts on both iOS and Android through a single incoming call, then using the compromised account to spread automatically to the victim’s contacts, in what the company describes as the first zero-click worm demonstrated against a mainstream messaging app on both platforms.

Attacker Calls Victim, Victim Becomes Attacker

In a demonstration published September 8, 2026, Calif showed an Android phone calling an iPhone and taking over its WeChat account while the phone was still ringing, with no answer or user interaction required. The compromised iPhone then called a second Android phone and took control of it the same way, illustrating a self-propagating chain: attacker calls victim, victim becomes attacker, victim calls the next victim. Calif said the underlying issue is a memory-corruption bug in WeChat’s VoIP stack, and that because the caller must already be on the target’s contact list, the extra trust WeChat extends to contacts ends up working in the attacker’s favor once one account in a network is compromised. Once hijacked, an account can read and send messages, place calls, and act on the victim’s behalf.

Patched Before Public Disclosure

Calif reported the flaw to WeChat developer Tencent in July, and Tencent shipped version 8.0.77 for Android and 8.0.76 for iOS on August 21, 2026, mitigating the bug; Calif confirmed on August 28 that the specific exploit was also blocked on Tencent’s servers for all users regardless of app version. Tencent has not published a security advisory describing the flaw, and its release notes for the affected updates describe them only as general bug fixes. Researchers are advising WeChat users to keep the app updated, review their contact lists for unfamiliar connections, and treat unexpected incoming calls from known contacts with caution, since a compromised contact’s account could be used to continue the propagation chain.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *