WeChat Zero-Click Worm Exposed in New Security Advisory

WeChat zero-click worm exploiting WeChat VoIP memory corruption

Researchers at Calif developed the first zero-click worm for WeChat. This WeChat zero-click worm spreads through automated calls across iOS and Android platforms. Tencent has already mitigated this critical threat on their servers.

Why This Threat Matters

WeChat serves over a billion users globally. Therefore, a WeChat zero-click worm poses a massive risk to digital communities. As a result, attackers can hijack accounts and spread the infection from phone to phone. Specifically, Calif researchers state, “If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide.” Moreover, attackers could read messages, make calls, and fully control compromised devices.

How the Attack Works

The vulnerability stems from a memory corruption issue. This bug exists in the WeChat VoIP stack. Consequently, an attacker initiates a voice call to a victim. The exploit triggers while the phone is still ringing. The victim never needs to answer the call. However, declining the call only delays the attack. In fact, attackers can simply try again later. They can also use a compromised friend’s account to bypass trust barriers. Calif detailed their process in their research at WeWorm report.

Affected Versions

This exploit impacts WeChat apps on both iOS and Android. Specifically, versions prior to Android 8.0.77 are vulnerable. Similarly, iOS versions before 8.0.76 contain the flaw. Additionally, researchers built the worm using AI assistance. They achieved remote code execution in just two days.

Patch and Mitigation Steps

Tencent acted quickly after receiving the bug report in July 2026. Ultimately, they mitigated the exploit for all users on the server side. Next, they released patched app updates. Users must update to Android version 8.0.77 or later. iOS users need version 8.0.76 or newer. Currently, researchers report no confirmed exploitation in the wild. A private proof-of-concept exists at Calif.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply