thehackernews.com 8 Sept 2026, 11:54 UTC

WeChat Bug Let Attackers Hijack Accounts Through Silent Calls

CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS at security firm Calif demonstrated a zero-click worm capable of taking over a WeChat account via an incoming call, without the target needing to answer or interact with their device. In a three-phone demonstration, an Android device called an iPhone and seized control of the WeChat account on the iPhone; that compromised iPhone then used the same technique to take over a second Android device.

The attacker must be already on the target’s WeChat contact list, but Calif notes this is a relatively low bar because a compromised contact can be trusted by the platform, enabling further propagation.

Calif reported the flaw to Tencent in July and says Tencent has since blocked the exploit on its servers. There have been no reported real-world attacks at the time of the disclosure. The researchers emphasise that answering the call does not stop the attack—the caller can attempt again later, for example while the target is asleep. Tencent released updates to mitigate the bug: Android version 8.0.77 and iOS version 8.0.76, published on 21 August.

Calif states the servers-block mitigation was in place by 28 August, and Tencent’s release notes describe the update as bug fixes rather than a security advisory. As of 8 September, WeChat’s current version listed on the App Store shows 8.0.76 as the latest for iOS, with no public advisory identifying affected versions. The firms did not publish CVEs for the flaw, and it remains unclear whether other WeChat platforms (HarmonyOS, Windows, Mac, Linux) were affected.

View full article

Article by CyberSIXT