ZeroHour
Help Net Securitypublished ()ingested Zeljka Zorz

“Zero-click” WeChat worm could hijack accounts and spread via a single call

highVulnerabilityimportance 82
AI summary · glm-5.3-flash

Researchers discovered a critical memory corruption flaw in WeChat's VoIP stack enabling a zero-click worm, WeWorm, that hijacks accounts via calls; Tencent patched it.

Calif researchers weaponized a memory corruption issue in WeChat's VoIP stack into "WeWorm", a worm that spreads through WeChat calls without user interaction, hijacks each victim's account, and propagates via saved contacts across iOS and Android, potentially reaching millions of devices within hours. Exploitation takes seconds and grants full account control, and chaining with other reported Android/iOS bugs could lead to full device control. Tencent issued updated WeChat versions for iOS and Android and applied server-side mitigations; technical details remain withheld. WeChat has over a billion users, overwhelmingly in China.

  • Zero-click spread: worm triggers via incoming WeChat call, even unanswered unless declined within seconds
  • Memory corruption in the VoIP stack; chained device bugs could yield full smartphone control
  • Tencent patched via app updates and server-side mitigation; no user action required
  • Researchers used AI to find the bug and write the RCE exploit in about two days
VendorsTencent
ProductsWeChatWeWorm
OrganizationsCalif
CountriesChina
Full article450 words · extracted from helpnetsecurity.com · click to collapse

Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction.

WeChat WeWorm vulnerability exploit

During its rampage, the WeWorm compromises the WeChat account of each user, and uses the saved contacts to propagate itself further, potentially reaching millions of devices within hours.

The worm can hop from smartphone to smartphone, regardless of whether they are running iOS or Android, as shown in this demo:

“Simply by calling a victim, WeWorm can hijack their account and call their friends,” the researchers explained.

“Exploitation takes only seconds, and gives us full control of the WeChat account. We can read and send messages, make calls, and act on the victim’s behalf. Chained with other Android and iOS bugs we’ve reported and are helping fix, it can lead to full control of the device.”

The worm will spread whether or not the victim answers the call. It will fail only if the victim declines the call within a few seconds, but the attacker can simply call again when the victim is asleep or otherwise unable to decline the call.

A vulnerability in WeChat’s VoIP stack

WeChat is a Chinese “super app” that combines a wide variety of capabilities:

  • Text, voice, and video messaging
  • Mobile payment
  • Shopping, ride-hailing, food delivery, government services
  • Social media, and more.

The app is used by over a billion users, who are overwhelmingly based in China.

“Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week,” the researchers stated.

Even though they reported the flaw to Tencent – which mitigated the bug by issuing new versions of the WeChat app for iOS and Android and later mitigated the exploit for all users on the server side – and even though users don’t need to take any action to keep their WeChat accounts and smartphones protected, the researchers are keeping the technical details under wraps.

However, they confirmed that it’s a “memory corruption issue in WeChat’s VoIP stack.”

“We are publishing our findings to raise public awareness. These capabilities have existed for a long time in the hands of well-funded, sophisticated actors. What’s different now is that AI is putting these capabilities in the hands of less skilled actors, leaving ordinary users at unprecedented risk,” the researchers noted, and urged for world governments to collaborate with the private industry “on developing and deploying AI to make the world safer for everyone.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/08/wechat-weworm-vulnerability-exploit-account-hijacking/