securityaffairs.com 8 Sept 2026, 18:09 UTC

WeChat Patches Zero Click Worm That Spreads Through Incoming Calls

WeChat Patches Zero Click Worm That Spreads Through Incoming Calls
CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS have demonstrated a WeChat worm that can take over a target account through an incoming call, without the victim needing to answer or interact with the phone. The attack relies on a memory corruption flaw in the app’s VoIP system and only works if the caller appears in the victim’s WeChat contacts.

In a controlled demo, the researchers used three test devices to show the worm spreading: compromising one device allowed the attacker to control the victim’s account and then call another contact, effectively propagating the worm between phones in seconds.

Tencent has addressed the flaw by releasing Android 8.0.77 and iOS 8.0.76 updates. The researchers emphasise that there is currently no public evidence of real-world exploitation, and defenders have no clear indicators to search for at present. They also note that the attack can compromise full device control and that the attacker can attempt the call again if the victim does not answer or interacts minimally with the device.

The research highlights how zero-click vulnerabilities in messaging apps can be dangerous, and the team suggests that AI-assisted tooling is lowering the barrier to developing such exploits. The disclosure aims to raise awareness and encourage collaboration among governments and platform providers to bolster AI security and reduce similar risks in the future.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline