Back Helpnetsecurity "Zero-click" WeChat worm could hijack accounts and spread via a single call
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction.
During its rampage, the WeWorm compromises the WeChat account of each user, and uses the saved contacts to propagate itself further, potentially reaching millions of devices within hours.
The worm can hop from smartphone to smartphone, regardless of whether they are running iOS or Android, as shown in this demo :
“Simply by calling a victim, WeWorm can hijack their account and call their friends,” the researchers explained.
“Exploitation takes only seconds, and gives us full control of the WeChat account. We can read and send messages, make calls, and act on the victim’s behalf. Chained with other Android and iOS bugs we’ve reported and are helping fix, it can lead to full control of the device.”
The worm will spread whether or not the victim answers the call. It will fail only if the victim declines the call within a few seconds, but the attacker can simply call again when the victim is asleep or otherwise unable to decline the call.
A vulnerability in WeChat’s VoIP stack
WeChat is a Chinese “super app” that combines a wide variety of capabilities:
Text, voice, and video messaging
Shopping, ride-hailing, food delivery, government services
Social media, and more.
The app is used by over a billion users, who are overwhelmingly based in China.
“Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in two days. Building the worm took one more week,” the researchers stated .
Even though they reported the flaw to Tencent – which mitigated the bug by issuing new versions of the WeChat app for iOS and Android and later mitigated the exploit for all users on the server side – and even though users don’t need to take any action to keep their WeChat accounts and smartphones protected, the researchers are keeping the technical details under wraps.
However, they confirmed that it’s a “memory corruption issue in WeChat’s VoIP stack.”
“We are publishing our findings to raise public awareness. These capabilities have existed for a long time in the hands of well-funded, sophisticated actors. What’s different now is that AI is putting these capabilities in the hands of less skilled actors, leaving ordinary users at unprecedented risk,” the researchers noted, and urged for world governments to collaborate with the private industry “on developing and deploying AI to make the world safer for everyone.”
Thomson Reuters reveals breach that exposed U.S. and Canadian court records
Your threat feed is someone else’s database: What ingesting malware intel at scale takes
When AI quietly breaks things, who pays?
Download: The High-Performance Team Playbook
Simplify security management with CIS SecureSuite Platform
Download: The IT and security field guide to AI adoption
Ransomware negotiation tactics have turned into a business process
September 2026 Patch Tuesday forecast: All we need is more time
OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets
Thomson Reuters reveals breach that exposed U.S. and Canadian court records
Your threat feed is someone else’s database: What ingesting malware intel at scale takes
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
