Latest News (EN)

WeChat flaw lets worm hijack accounts through phone calls

WeChat - Jirapong Manustrong / Shutterstock.com
Photo: WeChat - Jirapong Manustrong / Shutterstock.com
Share

Security specialists at Calif developed an automated worm that commandeers WeChat accounts via an incoming call, proving the technique across three test devices.

Targets do not need to answer incoming calls or tap their screens for the breach to trigger, provided the caller appears in their contacts. Calif disclosed the vulnerability to Tencent in July before the service provider blocked the exploit network-wide.

No malicious intrusions using this security loophole exist in verified incident logs. Zero-click attacks require no victim interaction to achieve infection. WhatsApp addressed a similar zero-interaction vulnerability in targeted incidents.

Answering the call does not halt the intrusion. The attack works silently.

Because the delivery mechanism requires caller placement on a victim’s WeChat contact directory, attackers leverage the inherent trust settings of hijacked accounts to target new acquaintances.

A demonstration showed an Android smartphone ringing an iPhone and seizing its account before the handset stopped alerting. The compromised iPhone then immediately placed a call to another Android terminal to reproduce the takeover.

Homem, celular
Homem, celular – dikushin/ Istockphoto.com

Researchers outlined attack pathways that theoretical intruders could take after completing an intrusion. Once the malicious routine executes, an intruder gains complete unauthorized authority over the compromised WeChat account, allowing the perpetrator to read incoming messages, dispatch new texts, initiate voice calls, and fully impersonate the genuine profile owner without altering the host mobile operating system. The exploit does not compromise the underlying operating system of the handset itself.

Beyond simple messaging functions, WeChat functions through mini programs, financial payments, and verified organizational accounts on the App Store. Tencent reported a combined monthly active user count of 1.439 billion across WeChat and Weixin on 30 June 2026.

Tencent published Android version 8.0.77 and iOS version 8.0.76 on 21 August, while Calif verified that server-side defenses neutralized the exploit on 28 August.

Tencent confirmed to researchers that server modifications mitigated the exploit for all account holders. Official release notes for the software patch in the App Store made no mention of the zero-click vulnerability, categorizing the update as ordinary bug fixes.

The defensive adjustment operates directly on company servers without forcing manual app installations. Installing the latest build remains the recommended baseline for device security. App Store listings on 8 September maintained version 8.0.76 as the current build.

Calif conducted exploit verification against Android version 8.0.76 and iOS version 8.0.75, which preceded the builds shipped on 21 August. Testing confirmed vulnerabilities across iOS 26.6 and unspecified prior Android versions without publishing a comprehensive inventory of exposed releases.

Tencent distributes separate WeChat builds across HarmonyOS, Windows, Mac, and Linux without publicly detailing if those desktop and alternative variants required identical security mitigations.

Calif withheld detailed code documentation ahead of an upcoming presentation at a technical security conference. Affected smartphone owners possess no technical log indicating whether their device received a weaponized call attempt.

Security checks conducted on 8 September identified no Common Vulnerabilities and Exposures identifier or public security advisory from Tencent, whose public disclosure page shows no new bulletins since April 2022.

Engineers deployed artificial intelligence tools to detect the flaw and assembled a functional arbitrary code execution exploit within two days. Building out the self-propagating worm component required an additional week.

Specialized prompts guided an automated intelligence model to survey communication application architectures and uncover viable attack surfaces.

Project logs document that engineers detected the bug on 23 July, completed the Android exploit on 30 July, and finished the multi-device worm demonstration on 11 August. The published record does not clarify whether the shorter timeframes measure active development hours or consecutive days.

Share

More news in Latest News (EN)

See more