← Latest briefing

Technology

Researchers demonstrate zero-click WeChat worm using calling flaw

Hacker News reports that security firm Calif showcased a zero-click exploit against WeChat calls before Tencent addressed the issue.

The short version

  • Security firm Calif created WeWorm, a proof-of-concept worm capable of hijacking WeChat accounts on iOS and Android when a device rings.[Hacker News]
  • The vulnerability requires the attacker to be in the target's contacts, though compromised accounts could propagate the exploit.[Hacker News]
  • Calif reported the memory corruption vulnerability to Tencent in July 2026, and Tencent mitigated the issue server-side in August.[Hacker News]

Key facts

  • Security firm Calif demonstrated WeWorm, described as a zero-click worm spreading via WeChat calls on Android and iOS.[Hacker News]
  • The exploit can take over an account while the phone is ringing without requiring the victim to answer.[Hacker News]
  • An attacker must be on the victim's friend list to launch the exploit.[Hacker News]
  • Calif reported submitting the underlying memory corruption bug to Tencent on July 24, 2026.[Hacker News]
  • Tencent mitigated the vulnerability on the server side for all users by August 28, 2026.[Hacker News]

What remains uncertain

  • Specific technical details regarding the memory corruption flaw in WeChat's VoIP stack remain withheld by researchers.[Hacker News]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.