AIO APEX

Zero-click worm hijacked WeChat accounts on iPhone and Android through a ringing call

The Hacker News
Share:
Zero-click worm hijacked WeChat accounts on iPhone and Android through a ringing call

Security researchers at Calif disclosed on September 8 a zero-click worm that could take full control of a WeChat account the instant an infected contact placed a call — before the phone was even answered. The exploit worked across both iPhone and Android, and Calif demonstrated it propagating device to device: an Android phone called an iPhone and hijacked its WeChat account while the phone was still ringing, and the compromised iPhone then called a second Android phone and took control of that account the same way.

What makes this exploit unusually severe is what it did not require. The person receiving the call did not have to answer, and even answering did not stop the attack — Calif said a victim who picked up simply heard silence while the takeover completed in the background. Once triggered, the attacker gained full control of the account: reading and sending messages, placing calls, and acting as the account owner in every respect a legitimate user could.

Why WeChat is a uniquely dangerous target

WeChat and its China-facing counterpart Weixin together count 1.439 billion monthly active users as of June 2026, and for the large majority of them the app is not just messaging — it is payments infrastructure, an identity layer for government and business services through mini programs, and often the primary way small merchants take orders and get paid. A worm capable of self-propagating through the contact graph without any user action is the closest thing to a worst-case scenario for a platform of that scale: account takeover doesn't just expose chat history, it opens a direct line to a victim's WeChat Pay balance and linked bank accounts, and a self-spreading exploit could in principle move through a social graph faster than any patch could reach affected devices.

Tencent's response, at least, was fast once the report reached them. The company shipped app updates — version 8.0.77 for Android and 8.0.76 for iOS — on August 21, and Calif confirmed by August 28 that the underlying flaw was also blocked at the server level, meaning the fix does not actually depend on users updating their app. That server-side kill switch is the main reason this vulnerability did not turn into a live worm event: Tencent could shut the exploit path down centrally rather than waiting on a slow update rollout across well over a billion devices.

No CVE, no public advisory — and that's a pattern

As of September 8, there is still no CVE identifier assigned to this flaw and no advisory published on Tencent's own security response site, despite the fix having shipped nearly three weeks earlier. This is consistent with how Tencent has historically handled WeChat security issues: fixes ship quietly, disclosure is minimal, and outside researchers are often the only public source of technical detail. For a platform this systemically important — WeChat functions as critical infrastructure in China in a way few Western apps do for any single country — the absence of a CVE and public advisory means enterprise security teams and researchers tracking the app's attack surface have no official record to work from.

The practical lesson for anyone running a large messaging or payments platform is less about this specific bug and more about the response model: a zero-click, call-triggered exploit is about as bad as vulnerability classes get, and the only thing that prevented a worm outbreak at global scale was the ability to kill the exploit path server-side without waiting for client updates. Any platform that cannot patch centrally — anything relying purely on app-store update cycles — should treat this incident as a reason to build that server-side kill-switch capability now, before it needs it.

As first reported by The Hacker News, citing research from security firm Calif published September 8, 2026.

Originally reported by The Hacker News. Read the original article for additional details.

View original source
Share: