WeChat Worm Spreads Via 0-Click Calls on iOS, Android
Key Takeaways A proof-of-concept worm, dubbed “WeWorm,” demonstrated zero-click propagation through WeChat voice calls on both iOS and Android. The exploit leveraged a memory-corruption...
Key Takeaways
- A proof-of-concept worm, dubbed “WeWorm,” demonstrated zero-click propagation through WeChat voice calls on both iOS and Android.
- The exploit leveraged a memory-corruption vulnerability in WeChat’s VoIP stack, allowing account compromise without user interaction.
- Tencent, WeChat’s developer, was notified in July 2026 and has since patched the vulnerability, making a fix available to users.
- The research highlights the potential for widespread, wormable attacks within global mobile messaging ecosystems, even if the attacker must be a pre-existing contact.
Zero-Click WeChat Worm Demonstrates Cross-Platform Account Takeover
Cybersecurity researchers have unveiled a proof-of-concept worm, “WeWorm,” capable of spreading across WeChat accounts on both iOS and Android devices through zero-click voice calls. The exploit, detailed by Calif, demonstrated the ability to compromise a target’s WeChat account in mere seconds, without any interaction from the victim, such as answering the call.
Table Of Content
Calif reported the vulnerability to Tencent, the developer of WeChat, in July 2026. Tencent has since mitigated the exploit, releasing patches to protect its vast user base. However, the research serves as a critical warning regarding the potential for mobile messaging applications to become fertile ground for wormable attacks on a global scale.
WeChat’s Massive Attack Surface
WeChat is far from a niche application. As of the end of Q1 2026, Tencent reported that Weixin and WeChat combined surpassed 1.4 billion monthly active users. WeChat’s official site further emphasizes its reach, serving over a billion users with chat and call functionalities across major mobile and desktop platforms.
This immense user base amplifies the alarm raised by Calif’s demonstration. The memory-corruption flaw discovered within the app’s Voice over IP (VoIP) stack is not merely another messaging bug; it represents a significant potential entry point into one of the world’s most deeply integrated communications ecosystems.
The WeWorm Mechanism: A Zero-Click Threat
According to Calif’s public research listing, published on September 8, 2026, WeWorm is described as “the first zero-click worm to spread through WeChat calls across iOS and Android.” The research was released as part of Calif’s broader work on Android security.
Calif framed the discovery not as a theoretical possibility but as a concrete demonstration of how trusted messaging relationships can be weaponized. A single compromised contact could become the initial launch point for attacks against everyone within that individual’s social network, leveraging pre-existing trust relationships for propagation.
The company’s demonstration chain reportedly involved three devices to validate cross-platform propagation. An initial attack was launched from a Pixel 10a, which called an iPhone 17e. The vulnerability was exploited while the iPhone was still ringing, compromising the device. Subsequently, the now-compromised iPhone was used to call another Pixel 10a, which was similarly taken over.
This sequence illustrates the textbook definition of a wormable condition in a communications application: an attacker calls a victim, the victim’s device becomes an attacker, and the infection continues with minimal friction.
The “zero-click” nature of the exploit makes this scenario particularly dangerous. Calif emphasized that victims do not need to answer the call or interact with their device in any way for the exploitation to succeed. Even if a user were to answer, they would hear nothing while the compromise proceeds in the background. This places WeWorm within the most concerning category of mobile exploits, where standard user vigilance offers little defense, as there are no malicious links to avoid or attachments to reject.
Account Takeover and Broader Implications
Calif’s research indicates that successful exploitation yields full control over the victim’s WeChat account. This includes the ability to read and send messages, initiate calls, and perform any action on the user’s behalf within the application. Such a level of account takeover is inherently severe, facilitating identity abuse, surveillance, fraud, and lateral targeting within an organization or social network.
Furthermore, Calif suggested that this access, when combined with additional device-level vulnerabilities, could potentially be escalated to full control over the underlying Android or iOS operating system. This possibility is linked to Calif’s broader AI-assisted exploit research, including projects like “OEMpocalypse” on Android, which has explored pathways from app-level access to root privileges across various vendor ecosystems.
While one condition slightly restricts the attack surface—the attacker must already be on the victim’s friend list—Calif argued that this is a weak barrier in real-world scenarios. Once a single trusted contact is compromised, their account can be leveraged to reach additional friends, transforming the victim’s social trust network into the worm’s propagation layer. This pattern is a recurring and troubling theme in modern communications security, where convenience-oriented safety features and trust assumptions can become force multipliers for adversaries once an initial foothold is established.
Technical Details and Future Outlook
The technical root cause of WeWorm, according to Calif, is a memory-corruption bug within WeChat’s VoIP stack. The company is currently withholding full exploit details, intending to present them at a future conference. This restraint is crucial, as memory-corruption flaws in real-time communications code represent some of the most sensitive bug classes in mobile security, especially when they reside in call-handling paths that process network data before any user interaction.
Calif also hinted that this specific bug might be indicative of a broader class of “unconventional attack surfaces” prevalent across messaging applications, suggesting that similar issues could exist in other platforms rich in calling and media features.
Though WeWorm is a proof-of-concept demonstration, its significance is profound. Calif has effectively shown that mobile messaging worms are no longer a theoretical threat or a topic confined to conference discussions. They are a practical research outcome in 2026, developed against one of the world’s largest communications platforms, with development potentially accelerated by AI-assisted techniques.
What You Should Do
- Ensure your WeChat application is updated to the latest version immediately to receive the patch released by Tencent.
- Maintain strong security hygiene across all mobile applications, regularly checking for and installing updates.
- Exercise caution with unsolicited calls, even from known contacts, as their accounts could be compromised.
- Enable multi-factor authentication (MFA) on your WeChat account and other critical applications to add an extra layer of security against account takeover.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.