Skip to content
Zero-click worm spreads on iPhones and Android via WeChat calls

Zero-click worm spreads on iPhones and Android via WeChat calls

Cyberinsider September 8, 2026

A zero-click worm can spread between iPhones and Android devices through WeChat calls, allowing attackers to hijack accounts even without victims answering.

Dubbed WeWorm, the proof-of-concept attack exploits a memory corruption vulnerability in WeChat’s Voice-over-IP (VoIP) stack. Calif reported the flaw to Tencent in July, and the company has since deployed mitigations that the researchers say block the exploit for all users.

Calif says its researchers discovered the vulnerability with the help of AI and developed the first remote code execution (RCE) exploit in roughly two days. The team completed an Android exploit on July 30, an iOS version on August 2, and a polished cross-platform worm demonstration by August 11.

WeChat is Tencent’s messaging and social platform and is deeply embedded in everyday communications and services in China, while also being widely used by Chinese communities worldwide. With a user base exceeding one billion accounts, a remotely exploitable flaw in its calling infrastructure could give attackers an unusually large target population.

To demonstrate the attack, Calif used three phones: two Pixel 10a Android devices and an iPhone 17e. The first Android phone called the iPhone, exploited WeChat while the device was still ringing, and gained control of the victim’s account. The compromised iPhone then automatically became the attacker and called the second Android phone, compromising it in the same way.

The victim does not need to answer the incoming call. Calif says exploitation completes within seconds and can provide control over the WeChat account, including the ability to read and send messages, place calls, and impersonate the victim.

Answering the malicious call does not prevent exploitation, while declining it interrupts that particular attempt. However, an attacker could retry later.

The exploit does have one important limitation: the calling account must already be on the victim’s WeChat friend list. Calif argues this would not necessarily stop worm-like propagation because an attacker could first compromise an existing and then use that trusted account to target additional people.

The underlying flaw is a memory corruption issue in WeChat’s VoIP implementation, but Calif is withholding technical details while additional work is underway on similar messaging-app attack surfaces. The researchers plan to disclose the full analysis at a future conference.

Tencent released WeChat Android 8.0.77 and iOS 8.0.76 on August 21. Calif subsequently confirmed on August 28 that the exploit had also been mitigated server-side for all users, before sharing its complete analysis and working exploits with Tencent on September 3.

ShinyHunters claims breach of Florida DMV, threatens data leak

Google warns hackers are deploying AI agents in autonomous attacks

LG Smart TVs found scanning networks for nearby devices

New attack eavesdrops on headphone audio from 30 meters away

Surfshark announces acquisition of data-removal service Optery

Bimbo Bakeries confirms data stolen in Oracle EBS zero-day attack

Amar Ćemanović is an experienced editor and trained engineer with a keen eye for detail and a passion for technology. Based in Bosnia, Amar specializes in producing high-quality, engaging content. He holds a Master’s degree in engineering, which helps him maintain a meticulous approach to all editorial work. Amar brings a well-rounded knowledge base, covering everything from tech solutions to privacy tools.

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Malware (1)

Platforms (3)