news.mlab.sh
Back to the feed
threat-intel

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

High
Summary

Researchers at Calif discovered a zero-click worm that allows attackers to take over WeChat accounts via incoming calls, even without the target answering. The worm leverages WeChat's trust mechanism to gain control, and Tencent has since blocked the exploit for all users. The vulnerability was discovered in July and patched in August, but it remains unclear which older versions were affected.

Researchers at Calif discovered a zero-click worm that allows attackers to take over WeChat accounts via incoming calls, even without the target answering. The worm leverages WeChat's trust mechanism to gain control, and Tencent has since blocked the exploit for all users. The vulnerability was discovered in July and patched in August, but it remains unclear which older versions were affected.

Answering the call does not stop the attack. Calif said a person who picks up hears nothing and the exploit still works. Declining the call ends that attempt, but the attacker can call again later, for example while the target is asleep. The caller has to be on the target's WeChat contact list. Calif said that is not much of a barrier, because once a contact is taken over, the extra trust WeChat gives to contacts works for the attacker rather than the user.

That handover is the part the demo shows. One Android phone called an iPhone and took over its WeChat while the phone was still ringing. The compromised iPhone then called a second Android phone and took control of it the same way. Calif's post describes routes an attacker could use rather than ones it tested. Once the exploit runs, the researchers said, the attacker has full control of the WeChat account and can read and send messages, make calls, and act as the account's owner.

For many users, that account is not only a chat app. WeChat's App Store listing covers payments, official accounts and mini programs inside the app. Tencent put the combined monthly active users of WeChat and Weixin at 1.439 billion as of 30 June 2026 in its second-quarter results.

Tencent released version 8.0.77 for Android and 8.0.76 for iOS on 21 August, according to its own release log. Calif said those releases mitigated the bug and that, on 28 August, it confirmed the exploit was blocked on Tencent's servers as well. Tencent has published no advisory about the flaw, and its release notes for the iOS version and its App Store entry describe the update as only bug fixes.

According to Calif, the block runs on Tencent's servers, so it does not require users to install anything. Running a current version is still the safer choice, and on 8 September that listing showed 8.0.76, released on 21 August, as the current version. Neither Calif nor Tencent has published which WeChat versions were affected, so a user cannot check whether the version they ran in July or August was one of them.

Tencent also ships WeChat clients for HarmonyOS, Windows, Mac and Linux on their own release schedules, and neither company has said whether the flaw reached any of them. Calif is holding back the technical details and plans to present the full analysis at a conference. It has not published anything a defender could search for, and there is no way for a user to tell whether they were called.

Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent's security response site, which lists the latest announcement as April 2022. The Hacker News has contacted Tencent and Calif for comment. Calif said it worked with AI to find the bug and write the first exploit that could run code on the phone in about two days. Building the worm took another week, it said.

Read the full article at The Hacker News