WeChat worm could pwn a friend before they even answered the call
Calif researchers demoed WeWorm, a zero-click WeChat VoIP memory-corruption worm enabling account takeover; Tencent patched it August 21.
Security firm Calif found a memory corruption bug in WeChat's VoIP stack that let a trusted contact take over a user's account simply by calling them, without the call being answered. The demo worm then called the victim's contacts to self-propagate across iOS and Android; declining the call prevented infection. Tencent pushed fixes on August 21, and Calif said chaining the bug with other Android and iOS flaws could yield full device control. Calif used AI to find the vulnerability and build its first RCE exploit in about two days.
- WeChat has over 1.4 billion monthly active users, amplifying potential worm impact.
- Exploit takes seconds and grants full account control: reading and sending messages, making calls.
- Attacker must be on the victim's friends list, but compromised accounts can target trusted contacts.
- Chaining with bugs like OEMpocalypse techniques could compromise entire devices.
- Full technical analysis is planned for presentation at an upcoming conference.
Full article478 words · extracted from theregister.com · click to collapse
Security
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
Tencent has patched up a zero-click vulnerability that security researchers used to create a worm capable of spreading through calls on WeChat.
With more than 1.4 billion monthly active users, WeChat is among the most popular apps in the world. According to researchers at Calif, its VoIP stack contained a memory corruption bug that could enable a trusted contact to take control of a user's account simply by calling them.
Calif called the flaw WeWorm, describing it as the first zero-click worm capable of spreading through WeChat calls on both iOS and Android.
REG AD
Calif released a demo of the vulnerability in action this week, and although Tencent has pushed fixes to address the attack on August 21, the team that found it is still withholding key details.
REG AD
In Calif's demonstration, the exploit took control of a victim's WeChat account within seconds, without the recipient answering the call. The compromised account then called another contact and repeated the process without user interaction.
Declining the call stopped infection, but answering it or allowing it to continue ringing did not. An attacker could also try again when the recipient was away from the phone, the researchers said.
"Exploitation takes only seconds, and gives us full control of the WeChat account," Calif said. "We can read and send messages, make calls, and act on the victim's behalf."
The exploit requires the attacker to be on the victim's friends list. Calif argued that this offered limited protection because a compromised account could be used to target its trusted contacts.
Calif said the WeWorm exploit could be chained with other vulnerabilities to compromise an entire device rather than only a WeChat account. It did not disclose the full attack chain.
"Chained with other Android and iOS bugs we've reported and are helping fix, it can lead to full control of the device," the researchers said.
"[Attackers] could exploit another app, gain root access using techniques like those in OEMpocalypse, take over the victim's WeChat app, and use it to attack you."
Calif said it used AI to find the vulnerability and develop its first remote code execution (RCE) exploit in about two days. Tencent later confirmed the researchers' findings.
REG AD
The researchers said they published their high-level findings to highlight how AI could make such capabilities available beyond "well-funded, sophisticated actors."
Calif plans to present the full analysis of WeWorm "at an upcoming conference."
Ryan Fedasiuk, an adjunct assistant professor in Georgetown University's Security Studies Program, described the discovery of WeWorm as "an extremely serious incident."
He called on the US and China to maintain open communication and share information as AI increases the potential scale and severity of cyber threats.
The Register asked Tencent for additional comment. ®
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/09/wechat-worm-could-pwn-a-friend-before-they-even-answered-the-call/5295234