ZeroHour
Story · 1 source · 1 articlefirst updated ()

WeWorm: Calif Research builds AI-discovered zero-click WeChat worm that hijacked accounts via unanswered calls; Tencent patched in August

highExploit / PoCimportance 82
What's new: This is the first merged summary of this story — there is no prior coverage to compare. All five reports (Sept 8–10, 2026) are consistent; the only variances are precision of figures, where the most specific data points were adopted: 1.418 billion combined MAU for WeChat/Weixin (end of 2025) and an August 21 patch date per The Register.
Merged summary · glm-5.3 · rewritten as coverage arrives

Security firm Calif Research weaponized a memory-corruption flaw in WeChat's VoIP stack into WeWorm, a zero-click worm that spreads via incoming WeChat calls without any user interaction and grants full account control; Tencent patched it in WeChat Android…

Calif Research found a memory-corruption flaw in WeChat's VoIP stack in July 2026 using LLM-assisted analysis (open-weight and frontier models), producing a working remote-code-execution exploit in about two days and spending roughly one additional week building the worm. The result, WeWorm, is described as the first zero-click worm to spread through WeChat calls across iOS and Android: a crafted incoming call triggers exploitation even if the victim never answers — and victims hear nothing if they do. Declining the call blocks that attempt, though attackers can simply retry later. The attacker must be on the victim's friend list, a barrier bypassed by first compromising a contact, after which the worm calls the victim's saved contacts to self-propagate. Successful exploitation grants full account control — reading and sending messages and making calls — and chaining the bug with other reported Android/iOS flaws (e.g., OEMpocalypse techniques) could yield full device control. In a demo, chained calls compromised three test phones in seconds, and researchers estimated potential spread to millions of devices within hours, given WeChat and Weixin's reported 1.418 billion combined monthly active users at the end of 2025. Tencent confirmed the bug and shipped fixes in WeChat Android 8.0.77 and iOS 8.0.76 in August (The Register reports patches were pushed August 21), alongside server-side mitigations. No in-the-wild exploitation has been observed; technical details remain withheld, with a full technical analysis planned for an upcoming conference.

  • Vulnerability: memory corruption in WeChat's VoIP stack enabling zero-click remote code execution via an incoming call, with no user interaction required.
  • WeWorm is billed as the first zero-click worm spreading through WeChat calls on both iOS and Android.
  • Exploitation succeeds even if the call is never answered; declining the call blocks that specific attempt, but attackers can retry later.
  • The attacker must be on the victim's WeChat friend list — achievable by compromising one contact first, after which the worm propagates via the victim's saved contacts.
  • Successful exploitation grants full account control (read/send messages, make calls); chaining with other Android/iOS bugs such as OEMpocalypse techniques could compromise entire devices.
  • In a demo, the worm compromised three test phones in seconds; researchers estimated it could reach millions of devices within hours.
  • User base: WeChat and Weixin reported 1.418 billion combined monthly active users at the end of 2025.
  • Discovery timeline: flaw found in July 2026; AI helped find the bug and write the RCE exploit in about two days, and building the worm took roughly one more week — work researchers say previously took larger teams months.

Coverage timeline

  1. · 8d ago
    Help Net Security· 82
    “Zero-click” WeChat worm could hijack accounts and spread via a single call

    Researchers discovered a critical memory corruption flaw in WeChat's VoIP stack enabling a zero-click worm, WeWorm, that hijacks accounts via calls; Tencent patched it.