Zero-Click 'WeWorm' Hijacked WeChat Accounts via Unanswered VoIP Calls; Tencent Patched in August
Calif researchers used AI to find and exploit a memory-corruption flaw in WeChat's VoIP stack, building WeWorm — described as the first zero-click worm spreading via WeChat calls on iOS and Android — which Tencent patched in Android 8.0.77 and iOS 8.0.76 in…
Researchers at Calif discovered a memory corruption bug in WeChat's VoIP stack in July 2026 using LLM-assisted analysis (open-weight and frontier models), writing a working remote code execution exploit in about two days and the full worm in one additional week — work the researchers say previously took larger teams months, with humans now mainly supplying judgment on targeting and safe testing. The result, WeWorm, is described as the first zero-click worm to spread through WeChat calls on iOS and Android: a crafted incoming call yields code execution with no user interaction, succeeding even if the victim never answers (and victims hear nothing even if they do), granting full control of the WeChat account — reading and sending messages and making calls. The attacker must be on the victim's friend list, but the worm overcomes this by first compromising a contact and then calling their friends, chained across three Android and iOS test phones in seconds in a demo. Declining a call blocks that specific attempt, though attackers can retry later. Calif said chaining the bug with other Android and iOS flaws, such as OEMpocalypse techniques, could compromise entire devices. Tencent confirmed the flaw and shipped patches in WeChat Android 8.0.77 and iOS 8.0.76 released in August (The Register dates the fixes to August 21); researchers found no evidence of real-world exploitation, with testing done on test phones only. WeChat and Weixin reported 1.418 billion combined monthly active users at the end of 2025, amplifying the potential worm impact. A full technical analysis is planned for presentation at an upcoming conference.
- Flaw: memory corruption in WeChat's VoIP stack, discovered by Calif in July 2026
- WeWorm is described as the first zero-click worm spreading through WeChat calls on iOS and Android
- Exploit requires no user interaction; works even if the call is never answered, and victims hear nothing even if they do answer
- Grants full WeChat account control: reading and sending messages and making calls
- Attacker must be on the victim's friend list; the worm achieves this by compromising a trusted contact first, then calling their friends
- Demo chained the exploit across three Android and iOS test phones in seconds; no in-the-wild exploitation reported
- Declining the call blocks that attempt, but attackers can retry later
- AI/LLMs (open-weight and frontier models) helped find the bug and build the first RCE exploit in about two days; the worm took one more week
Coverage timelineoldest first · each row is one article
- · 7d agoWeChat Worm Can Hijack Accounts Without Victims Answering Calls
Security Affairs· 66
Researchers demoed WeWorm, a zero-click WeChat worm hijacking accounts via incoming VoIP calls using a memory corruption flaw; Tencent patched it in August.