Thehackernews
WeWorm: Zero-Click Worm Exploits WeChat Calls
Article Content
Calif has developed WeWorm, a zero-click worm that spreads through WeChat voice calls on iOS and Android devices. This exploit allows an attacker to take over a victim's WeChat account simply by calling them, without requiring any interaction from the victim. The attacker must be on the victim's WeChat contact list, but once one account is compromised, the worm can spread rapidly. Calif reported the vulnerability to Tencent in July 2026, and Tencent has since mitigated the exploit for all users. No active attacks exploiting this vulnerability have been reported. The potential impact is significant, with WeChat having over 1.4 billion users. The worm demonstrates how AI can facilitate the creation of sophisticated attacks quickly. Users are advised to ensure they are running the latest version of WeChat to mitigate risks.
Key Points: • WeWorm can compromise WeChat accounts via zero-click calls. • The exploit requires the attacker to be a contact of the victim. • Tencent has mitigated the vulnerability, but no active attacks have been reported.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.