WeChat Zero-Click Worm Hijacked Accounts Through Incoming Calls
Vulnerabilities

Illustrative image generated with AI

WeChat Zero-Click Worm Hijacked Accounts Through Incoming Calls

A zero-click WeChat flaw let contacts hijack accounts via incoming calls and spread as a worm. Fixed in August updates with server-side blocking.

Text generated by artificial intelligence, published without human review. AI transparency

A zero-click vulnerability in WeChat allowed a caller to take over another user’s account while the target’s phone was still ringing, without requiring the call to be answered.

Security company Calif developed a working exploit and then converted it into a worm capable of moving between contacts. In its demonstration, an Android phone compromised an iPhone, which subsequently called and compromised a second Android device.

The caller had to be an existing WeChat contact. That condition limits the initial attack surface, but it offers little protection once an account is hijacked: the compromised identity can call trusted contacts and continue the infection chain.

Calif reported the flaw to Tencent in July. WeChat 8.0.77 for Android and 8.0.76 for iOS, released on 21 August, mitigated the vulnerability, according to the researchers. Tencent also implemented server-side blocking, which Calif confirmed on 28 August.

No exploitation in real-world attacks has been reported.

The Call Itself Triggered the Exploit

The vulnerability did not depend on social engineering, malicious links, attachments, or approval prompts. Receiving the WeChat call was sufficient to trigger the exploit.

Calif said the attack continued even if the victim answered. In that scenario, the target heard no audio while exploitation proceeded in the background. Declining the call stopped that particular attempt, but the attacker could simply try again later, including when the user was not actively handling the phone.

The public demonstration began with an Android device calling an iPhone through WeChat. The iPhone account was compromised before the ringing stopped. The hijacked account then placed a call to another Android phone and took control of its WeChat account through the same process.

This propagation model makes the contact requirement a potentially useful part of the attack rather than a durable barrier. A call from a known person is less likely to appear suspicious, and each newly compromised account provides another set of trusted relationships.

Calif has not released the technical details needed to reproduce the exploit. The company is withholding them until a conference presentation, so the vulnerable component, memory-corruption primitive, execution chain, and server interactions remain undisclosed.

Some attack routes have been described as possible rather than experimentally validated. The demonstrated behavior, however, established zero-click compromise and cross-platform propagation between Android and iOS accounts.

Account Control, Not Full Smartphone Control

Successful exploitation reportedly gave the attacker complete control over the victim’s WeChat account. That included the ability to read and send messages, place calls, and act as the legitimate account holder.

The vulnerability did not independently compromise the underlying smartphone. There is no claim that the worm provided unrestricted access to local files, other applications, microphones, cameras, or the operating system itself.

That distinction narrows the technical impact but does not make the compromise minor. WeChat accounts can be connected to payments, official accounts, and mini programs, extending the consequences beyond exposed conversations.

An attacker operating as the victim could potentially abuse existing relationships, interact with services available through the account, or use trusted contact status to reach additional targets. The exact post-compromise actions tested by Calif have not been fully disclosed.

The potential scale is considerable. Tencent reported that WeChat and Weixin had a combined 1.439 billion monthly active users as of 30 June 2026. There is no evidence that a large-scale infection occurred, but the size of the user base would have made a functioning worm especially dangerous.

Android and iOS Were Demonstrably Exposed

Tencent released WeChat 8.0.77 for Android and WeChat 8.0.76 for iOS on 21 August. Calif said both releases mitigated the issue.

On 8 September, version 8.0.76 remained the current release shown in the iOS listing. Users should install the newest available client for their platform, even though the server-side protection is expected to block Calif’s exploit without requiring an application update.

The full range of vulnerable versions is not known. Neither Tencent nor Calif has published an affected-version matrix, leaving users unable to establish which WeChat installations used during July or August were susceptible.

The status of other platforms is also unclear. Tencent distributes separate WeChat clients for HarmonyOS, Windows, Mac, and Linux, but neither organization has said whether those applications contained the vulnerable code or could receive the malicious call path.

The demonstrated worm moved between Android and iOS. That does not establish exposure on desktop systems or HarmonyOS, but it also does not rule it out.

Tencent Blocked the Exploit Without Publishing an Advisory

The mitigation has two layers. Updated Android and iOS clients contain changes that Calif associates with the fix, while Tencent’s server-side controls reportedly prevent the exploit from reaching users.

Calif confirmed the server block on 28 August. Because that protection operates within Tencent’s infrastructure, it should cover users who have not yet upgraded. Running a current client remains the safer option because server-side filtering does not clarify whether vulnerable code is still present in older installations.

Tencent has not published a dedicated security advisory explaining the root cause, affected releases, severity, or remediation. The iOS release notes and App Store entry refer only to bug fixes.

As of 8 September, no CVE identifier had been published, and there was no corresponding notice on Tencent’s security response site. The latest announcement listed there was from April 2022.

The lack of an advisory creates a visibility gap. Administrators cannot map the flaw to specific software inventories, verify whether every managed endpoint had a vulnerable build, or review technical compromise indicators.

AI Assisted the Initial Exploit Development

Calif said artificial intelligence helped its researchers identify the flaw and produce an initial exploit capable of executing code on the phone in approximately two days. Turning that initial capability into a propagating worm required another week, according to the company.

Its more detailed chronology states that the engineering team learned of the bug on 23 July, completed the first Android exploit on 30 July, and demonstrated the worm on 11 August.

Those calendar intervals do not align exactly with the stated two-day and one-week development periods. The difference may reflect working time, separate development phases, or different definitions of when exploit engineering began. Calif has not provided a more detailed reconciliation.

The AI claim is notable because it concerns exploit development rather than merely code review or vulnerability classification. However, the absence of technical documentation makes it impossible to assess which tasks the AI system performed, how much human guidance was required, or whether it materially accelerated the final worm.

What Users and Organizations Can Do

Users should update to the newest WeChat release available through an official distribution channel. Where applicable, the mitigated versions identified by Calif are:

  • Android: WeChat 8.0.77
  • iOS: WeChat 8.0.76

Tencent’s server-side defenses reportedly block the demonstrated exploit for all users. There is currently no published workaround beyond relying on that protection and keeping the client updated.

There are also no public indicators of compromise, exploit fingerprints, affected-version tables, or user-facing tools that can determine whether a suspicious incoming call carried the exploit. Call history alone cannot establish compromise.

Organizations that permit WeChat on managed devices should treat a hijacked account as more than a messaging incident. Investigations may need to consider unauthorized calls and messages, payment-related activity, mini-program interactions, and actions involving official accounts.

Unexpected outbound calls or messages may justify an account review, but they are not specific indicators of this worm. Calif and Tencent have not provided a reliable method for detecting past exploitation.

For now, the most consequential fact is also the most reassuring: the worm was demonstrated by researchers, Tencent has reportedly blocked it, and no attacks using the vulnerability have been reported.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsWeChat vulnerabilityzero-click exploitaccount hijackCalif researchiOS Android securityTencent fix
Back to home