SECURITYONLINE [.]info reports Calif Security researchers have unveiled WeWorm, described as the first zero-click worm capable of propagating through WeChat voice calls on both iOS and Android. The attack requires no user interaction beyond an incoming call; the victim does not need to answer or engage with the device, and the worm can spread as the compromised account places calls to the victim’s contacts.
In Calif’s framing, a single unanswered incoming call can hijack the target’s WeChat account within seconds, enabling the attacker to read and send messages, place calls, and act as the victim, with the compromised account subsequently contacting others and continuing the propagation cycle. The researchers emphasise that the root cause is a memory corruption flaw in WeChat’s VoIP call-handling stack, though full technical details are being withheld pending a conference presentation.
Evidence cited includes published WeWorm research and an expedited development timeline, with researchers describing rapid transition from bug discovery to a working exploit and a full worm demo in about two weeks.
Tencent has patched both server-side and client-side components. A server-side fix was released on 28 August 2026 for all users, and client updates—Android 8.0.77 and iOS 8.0.76—were deployed on 21 August 2026 to mitigate the client-side exposure. On 4 September, Tencent confirmed the vulnerability could be exploited for remote command execution.
The article notes that, while no exploitation in the wild has been publicly confirmed beyond Calif’s own PoCs, the combination of social trust within WeChat and the server/client patches means users should update to the latest versions and audit their contact lists for unfamiliar connections, remaining vigilant for unusual calls from known contacts. No CVE identifier has been assigned to this vulnerability as of the report.