Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Claude Mythos AI Autonomously Executes Full Cyber Kill Chain
September 8, 2026
WeChat Worm Spreads Via 0-Click Calls on iOS, Android
September 8, 2026
Critical Flaw in CrowdStrike Falcon Lets Attackers Disable Protection
September 8, 2026
Home/CyberSecurity News/WeChat Worm Spreads Via 0-Click Calls on iOS, Android
CyberSecurity News

WeChat Worm Spreads Via 0-Click Calls on iOS, Android

Key Takeaways A proof-of-concept worm, dubbed “WeWorm,” demonstrated zero-click propagation through WeChat voice calls on both iOS and Android. The exploit leveraged a memory-corruption...

Jennifer sherman
Jennifer sherman
September 8, 2026 5 Min Read
2 0

Key Takeaways

  • A proof-of-concept worm, dubbed “WeWorm,” demonstrated zero-click propagation through WeChat voice calls on both iOS and Android.
  • The exploit leveraged a memory-corruption vulnerability in WeChat’s VoIP stack, allowing account compromise without user interaction.
  • Tencent, WeChat’s developer, was notified in July 2026 and has since patched the vulnerability, making a fix available to users.
  • The research highlights the potential for widespread, wormable attacks within global mobile messaging ecosystems, even if the attacker must be a pre-existing contact.

Zero-Click WeChat Worm Demonstrates Cross-Platform Account Takeover

Cybersecurity researchers have unveiled a proof-of-concept worm, “WeWorm,” capable of spreading across WeChat accounts on both iOS and Android devices through zero-click voice calls. The exploit, detailed by Calif, demonstrated the ability to compromise a target’s WeChat account in mere seconds, without any interaction from the victim, such as answering the call.

Table Of Content

  • Key Takeaways
  • Zero-Click WeChat Worm Demonstrates Cross-Platform Account Takeover
  • WeChat’s Massive Attack Surface
  • The WeWorm Mechanism: A Zero-Click Threat
  • Account Takeover and Broader Implications
  • Technical Details and Future Outlook
  • What You Should Do

Calif reported the vulnerability to Tencent, the developer of WeChat, in July 2026. Tencent has since mitigated the exploit, releasing patches to protect its vast user base. However, the research serves as a critical warning regarding the potential for mobile messaging applications to become fertile ground for wormable attacks on a global scale.

WeChat’s Massive Attack Surface

WeChat is far from a niche application. As of the end of Q1 2026, Tencent reported that Weixin and WeChat combined surpassed 1.4 billion monthly active users. WeChat’s official site further emphasizes its reach, serving over a billion users with chat and call functionalities across major mobile and desktop platforms.

This immense user base amplifies the alarm raised by Calif’s demonstration. The memory-corruption flaw discovered within the app’s Voice over IP (VoIP) stack is not merely another messaging bug; it represents a significant potential entry point into one of the world’s most deeply integrated communications ecosystems.

The WeWorm Mechanism: A Zero-Click Threat

According to Calif’s public research listing, published on September 8, 2026, WeWorm is described as “the first zero-click worm to spread through WeChat calls across iOS and Android.” The research was released as part of Calif’s broader work on Android security.

Calif framed the discovery not as a theoretical possibility but as a concrete demonstration of how trusted messaging relationships can be weaponized. A single compromised contact could become the initial launch point for attacks against everyone within that individual’s social network, leveraging pre-existing trust relationships for propagation.

The company’s demonstration chain reportedly involved three devices to validate cross-platform propagation. An initial attack was launched from a Pixel 10a, which called an iPhone 17e. The vulnerability was exploited while the iPhone was still ringing, compromising the device. Subsequently, the now-compromised iPhone was used to call another Pixel 10a, which was similarly taken over.

This sequence illustrates the textbook definition of a wormable condition in a communications application: an attacker calls a victim, the victim’s device becomes an attacker, and the infection continues with minimal friction.

The “zero-click” nature of the exploit makes this scenario particularly dangerous. Calif emphasized that victims do not need to answer the call or interact with their device in any way for the exploitation to succeed. Even if a user were to answer, they would hear nothing while the compromise proceeds in the background. This places WeWorm within the most concerning category of mobile exploits, where standard user vigilance offers little defense, as there are no malicious links to avoid or attachments to reject.

Account Takeover and Broader Implications

Calif’s research indicates that successful exploitation yields full control over the victim’s WeChat account. This includes the ability to read and send messages, initiate calls, and perform any action on the user’s behalf within the application. Such a level of account takeover is inherently severe, facilitating identity abuse, surveillance, fraud, and lateral targeting within an organization or social network.

Furthermore, Calif suggested that this access, when combined with additional device-level vulnerabilities, could potentially be escalated to full control over the underlying Android or iOS operating system. This possibility is linked to Calif’s broader AI-assisted exploit research, including projects like “OEMpocalypse” on Android, which has explored pathways from app-level access to root privileges across various vendor ecosystems.

While one condition slightly restricts the attack surface—the attacker must already be on the victim’s friend list—Calif argued that this is a weak barrier in real-world scenarios. Once a single trusted contact is compromised, their account can be leveraged to reach additional friends, transforming the victim’s social trust network into the worm’s propagation layer. This pattern is a recurring and troubling theme in modern communications security, where convenience-oriented safety features and trust assumptions can become force multipliers for adversaries once an initial foothold is established.

Technical Details and Future Outlook

The technical root cause of WeWorm, according to Calif, is a memory-corruption bug within WeChat’s VoIP stack. The company is currently withholding full exploit details, intending to present them at a future conference. This restraint is crucial, as memory-corruption flaws in real-time communications code represent some of the most sensitive bug classes in mobile security, especially when they reside in call-handling paths that process network data before any user interaction.

Calif also hinted that this specific bug might be indicative of a broader class of “unconventional attack surfaces” prevalent across messaging applications, suggesting that similar issues could exist in other platforms rich in calling and media features.

Though WeWorm is a proof-of-concept demonstration, its significance is profound. Calif has effectively shown that mobile messaging worms are no longer a theoretical threat or a topic confined to conference discussions. They are a practical research outcome in 2026, developed against one of the world’s largest communications platforms, with development potentially accelerated by AI-assisted techniques.

What You Should Do

  • Ensure your WeChat application is updated to the latest version immediately to receive the patch released by Tencent.
  • Maintain strong security hygiene across all mobile applications, regularly checking for and installing updates.
  • Exercise caution with unsolicited calls, even from known contacts, as their accounts could be compromised.
  • Enable multi-factor authentication (MFA) on your WeChat account and other critical applications to add an extra layer of security against account takeover.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Flaw in CrowdStrike Falcon Lets Attackers Disable Protection

Next Post

Claude Mythos AI Autonomously Executes Full Cyber Kill Chain

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
US Offers $10M Reward for Iran IRGC Cyber Chief Linked to Critical Infrastructure Attacks
September 8, 2026
Best Managed XDR Services for 2026
September 8, 2026
Evilginx2 Phishing Steals Session Cookies, Bypasses Microsoft 365 MFA
September 8, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us