A team of researchers at Calif, a Palo Alto-based cybersecurity startup, says it has built a tool capable of hacking Android and iPhone devices via a simple incoming call. The exploit, named WeWorm, hinges on a remote code execution (RCE) flaw in WeChat’s VoIP stack. Calif claims this is the first zero-click worm to spread through WeChat calls on both iOS and Android.
The vulnerability was identified in July using a mix of large language models; the researchers did not disclose the models or provide technical vulnerability details. They indicated the issue is a memory corruption flaw in WeChat’s VoIP handling, which leverages the privileges granted to trusted contacts within the app. Tencent reportedly confirmed that exploitation could enable remote command execution and issued patched versions for Android (8.0.77) and iOS (8.0.76) after the disclosure dated 8 September 2026.
WeWorm reportedly grants attackers full control of a victim’s WeChat account, enabling reading and sending messages, making calls, and acting on the victim’s behalf. The victim need not interact with the call; even if the call is answered, they may hear nothing, and the exploit can succeed. Declining a call may halt a single attempt, but attackers can retry, for example while the user is asleep.
The attack requires the attacker to be on the victim’s friend list, though Calif argues this is not a substantial barrier since an attacker could compromise a friend’s account to reach the target. Calif also notes that when combined with other Android and iOS bugs, WeWorm could achieve full device control. The researchers assert the scale of such worms is now feasible with AI-assisted development, and that they developed the exploit and testing framework in about a week after initial vulnerability access. The disclosure was dated 8 September 2026.