WeChat Zero-Click Worm Exploit Took Accounts via Incoming Calls

A newly discovered worm vulnerability in WeChat allowed attackers to seize control of users’ accounts—without any action required on the target’s part. The issue, disclosed by security firm Calif, could be triggered simply by an incoming call from a contact. No answer, no tap, no interaction was needed for a full account takeover. 

Calif’s team built a proof-of-concept worm targeting both iPhone and Android devices. The exploit spread through incoming calls while the phone was still ringing. First, an Android phone called an iPhone and commandeered the WeChat account even before the call was answered. Then the compromised iPhone called second, taking over an Android account in the same way. 

How the Worm Works

The attack hinges on zero-click mechanics: the recipient doesn’t have to pick up. Declining the call terminates that particular attempt, but the exploit could be retried later—possibly when the target is asleep. If the call is answered, the exploit still succeeds even if the user hears nothing. Crucially, the attacker must already be in the victim’s WeChat contacts list. Calif emphasizes that this isn’t a high barrier since a single compromised contact can be used to spread trust inside WeChat. 

Once the worm executes, it grants full control over the WeChat account: sending and reading messages, making calls, and interacting as if the attacker were the account owner. However, it doesn’t grant control of the device itself. 

Response and Mitigation Steps

The bug was reported to Tencent in July. In response, Tencent rolled out patches in mid-August—version 8.0.77 for Android and 8.0.76 for iOS—addressing the vulnerability. Calif confirmed on August 28 that Tencent’s servers had blocked the exploit for all users. 

Although the server‐side mitigation means users aren’t required to upgrade immediately, running the patched client remains strongly recommended. As of September 8, the App Store was still listing version 8.0.76 as the current iOS release. Neither Tencent nor Calif have clarified which older versions were vulnerable, leaving many users unable to verify if they’ve been exposed. It’s also unknown whether non-mobile clients (Windows, Mac, Linux, HarmonyOS) were affected. Calif is withholding technical details until a conference presentation; no public indicator exists yet for detection. 

To find the exploit, Calif used an AI-based technique to detect the vulnerability and golfed together an initial exploit in roughly two days. Crafting the worm itself took about a week. Their engineering records point to discovery on July 23, first Android exploit on July 30, and a full worm demo by August 11. 

As of now, no attacks leveraging this flaw have been reported in the wild. Also, the flaw has yet to receive a CVE identifier or any security advisory from Tencent. The most recent Tencent security announcement remains from April 2022. 

Analytical Take: This WeChat zero-click worm is a stark reminder that even well-trusted messaging apps are vulnerable to sophisticated attacks exploiting minimal user interaction. The fact that an incoming call—whether answered or not—was enough to trigger a takeover underscores how trust boundaries (like contacts) can be weaponized. While Tencent’s patch and server blockade are welcome, the lack of transparency around affected versions and platforms raises concerns. Watch for disclosures about CVE assignment and more detailed mitigation guidance as this story develops. Users should verify their app versions immediately and exercise caution even with calls from known contacts.