A security firm has demonstrated a flaw in WeChat that let one account seize control of another simply by placing a call to it, whether or not the person on the other end ever picked up. The researchers chained the technique into a self-spreading worm that jumped between an Android handset and an iPhone and then on to a third device, each compromised account becoming the launch point for the next call. Tencent has since shipped fixes and blocked the technique on its own servers, so the demonstration describes a hole that has been closed rather than one still open. What makes it notable is less the bug itself than how quickly a small team assembled a working attack against an app with more than a billion users.
Three phones, two operating systems, and a call nobody answered
The firm behind the work, Calif, published its findings on 8 September and named the demonstration WeWorm, describing it as the first zero-click worm able to spread through WeChat calls across both iOS and Android. The setup was deliberately mundane: a Pixel 10a placed a call to an iPhone 17e and took over its WeChat account while the handset was still ringing. That compromised iPhone then called a second Pixel and did the same thing again. In the researchers’ phrasing, the attacker calls the victim, the victim becomes the attacker, and the victim calls the next victim.
“Zero-click” is the term of art for an attack that needs nothing from the target — no tapped link, no downloaded file, no answered call. According to Calif’s published account of the research, the takeover completed in seconds and handed the researchers full control of the account: reading and sending messages, placing calls, and acting as the account holder. Answering the call changed nothing, and a person who answered heard silence. Declining within a few seconds did defeat that particular attempt, but the researchers noted the obvious workaround available to a real attacker, which is to call again while the target is asleep.
Why a friend’s account is the way in
The attack carried one meaningful precondition: the caller had to already be on the target’s WeChat contact list. That sounds like a serious limit, and in isolation it is. The problem is that it stops being one as soon as the technique works at all, because the first compromised account arrives pre-loaded with a contact list full of people who trust it. Messaging platforms routinely grant contacts privileges that strangers do not have, and that design assumption is exactly what a worm turns inside out — the trust that makes a friend’s call safe is what makes a friend’s compromised account dangerous.
Scale is what turns that dynamic into a systemic risk. WeChat is not a single-purpose messenger but an everything app, bundling messaging, mobile payments, shopping, ride-hailing, food delivery and access to government services into one login, used by more than a billion people, overwhelmingly in China and across Chinese communities abroad. Calif estimated that an attacker who released the technique rather than reporting it could have reached over a billion phones or accounts. Coverage of the disclosure noted that a worm propagating through saved contacts could plausibly have reached millions of devices within hours.
What Tencent shipped, and when
The disclosure timeline the firm published is unusually specific. The bug was submitted to Tencent on 24 July. Tencent published WeChat versions 8.0.77 for Android and 8.0.76 for iOS on 21 August, which mitigated the flaw, and by 28 August the researchers had confirmed their exploit was also blocked on Tencent’s servers for all users. On 3 September the firm handed over its full technical analysis and working exploits, and Tencent confirmed the following day that the vulnerability could be used for remote command execution. The server-side block matters more than the app updates for ordinary users, because it does not depend on anyone installing anything.
One detail in the timeline is quietly telling. Between 25 and 28 July, shortly after the report was filed, the researchers’ own WeChat accounts were banned, then unbanned the next day — a reminder that the reporting process for a flaw of this size runs through the same automated enforcement systems as everything else.
Two days to a working exploit, one week to a worm
The finding the researchers themselves chose to foreground is not the bug but the schedule. Working with AI tooling, the team said it found the flaw and wrote the first remote code execution exploit in roughly two days, then spent about another week turning it into the worm demonstration. Their framing is that a worm of this scale used to be the kind of project that occupied a larger team for months, and that the human contribution had narrowed to judgment about what to target and how to test it safely.
Their stated conclusion is not that this argues for slowing the technology down. The vulnerabilities already exist, the argument runs, and what has changed is the speed at which they can be found and fixed — an advantage the researchers believe favours defenders, provided defenders are paying attention. They also invoked the precedent of WannaCry, which escaped from tooling that got loose before anyone was ready and went on to disrupt hospitals, as the reason to worry about a half-finished version of something like this leaking rather than about the finished research being published.
The technical details are deliberately missing
Calif has disclosed only that the flaw was a memory corruption issue in WeChat’s voice-over-IP stack, and is withholding the rest pending a conference presentation and further work with other app makers. The firm has said the same class of unconventional attack surface exists across other messaging apps, and that reducing it may require an industry-wide effort involving the platform owners themselves rather than individual developers.
For WeChat users, the practical position is that no action was ever required: the server-side mitigation covers everyone, including anyone still running an older build. The broader point the research leaves behind is about the calls a phone receives but never rings for, and how little of a messaging app’s attack surface is visible to the person holding it.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview