WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Vulnerability / Mobile SecurityResearchers at the security firm Calif have built a worm that takes 2026-9-8 11:54:29 Author: thehackernews.com(查看原文) 阅读量:3 收藏

Vulnerability / Mobile Security

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones.

The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since blocked the exploit for all users.

No attacks using the flaw have been reported, and Calif does not say there were any. Attacks that require no action from the target, known as zero-click attacks, are not new. Last year, WhatsApp patched a flaw it said may have been used in targeted attacks.

Answering the call does not stop the attack. Calif said a person who picks up hears nothing and the exploit still works. Declining the call ends that attempt, but the attacker can call again later, for example while the target is asleep.

The caller has to be on the target's WeChat contact list. Calif said that is not much of a barrier, because once a contact is taken over, the extra trust WeChat gives to contacts works for the attacker rather than the user.

That handover is the part the demo shows. One Android phone called an iPhone and took over its WeChat while the phone was still ringing. The compromised iPhone then called a second Android phone and took control of it the same way.

Calif's post describes routes an attacker could use rather than ones it tested. Once the exploit runs, the researchers said, the attacker has full control of the WeChat account and can read and send messages, make calls, and act as the account's owner. On its own, it does not give control of the phone itself.

For many users, that account is not only a chat app. WeChat's App Store listing covers payments, official accounts and mini programs inside the app. Tencent put the combined monthly active users of WeChat and Weixin at 1.439 billion as of 30 June 2026 in its second-quarter results.

Tencent released version 8.0.77 for Android and 8.0.76 for iOS on 21 August, according to its own release log. Calif said those releases mitigated the bug and that, on 28 August, it confirmed the exploit was blocked on Tencent's servers as well.

The researchers said Tencent has "mitigated our exploit for all users." Tencent has published no advisory about the flaw, and its release notes for the iOS version and its App Store entry describe the update as only bug fixes.

According to Calif, the block runs on Tencent's servers, so it does not require users to install anything. Running a current version is still the safer choice, and on 8 September that listing showed 8.0.76, released on 21 August, as the current version.

Neither Calif nor Tencent has published which WeChat versions were affected, so a user cannot check whether the version they ran in July or August was one of them.

Tencent also ships WeChat clients for HarmonyOS, Windows, Mac and Linux on their own release schedules, and neither company has said whether the flaw reached any of them.

Calif is holding back the technical details and plans to present the full analysis at a conference. It has not published anything a defender could search for, and there is no way for a user to tell whether they were called.

Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent's security response site, which lists the latest announcement as April 2022. The Hacker News has contacted Tencent and Calif for comment.

Calif said it worked with AI to find the bug and write the first exploit that could run code on the phone in about two days. Building the worm took another week, it said.

Its own timeline gives longer gaps. Its engineering team knew of the bug on 23 July, the first Android exploit was finished on 30 July, and the worm demo on 11 August. The post does not say whether the shorter figures count only working time.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
如有侵权请联系:admin#unsafe.sh