← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

WeChat Zero-Click Worm Demonstrated via Incoming Calls, Patched by Tencent

🔄 Updated 18h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Calif researchers created a zero-click worm for WeChat.
  • The worm exploited a flaw via incoming calls on iOS and Android.
  • Tencent patched the vulnerability in August 2026.
  • No real-world attacks using this flaw were reported.

Zero-Click Vulnerability Discovered

Security firm Calif developed a worm capable of taking over WeChat accounts through an incoming call. The exploit worked on both iPhone and Android devices, requiring no action from the recipient, such as answering or touching the phone. The only prerequisite was that the attacker needed to be an existing WeChat contact of the target.

Demonstration and Impact

Calif demonstrated the worm's spread by compromising an iPhone from an Android phone, then using the compromised iPhone to take over a second Android phone. Once exploited, the attacker gained full control of the WeChat account, enabling them to read and send messages, make calls, and act as the account owner. The exploit did not grant control over the phone itself, but WeChat's extensive features, including payments and mini-programs, made account compromise significant.

Tencent's Response and Patch

Calif reported the flaw to Tencent in July. Tencent subsequently released updates (version 8.0.77 for Android and 8.0.76 for iOS) on August 21, which mitigated the bug. By August 28, Calif confirmed that the exploit was also blocked on Tencent's servers, effectively patching the vulnerability for all users. No attacks leveraging this specific flaw were reported in the wild.

Significance of the Fix

The fix addresses a critical zero-click vulnerability on a platform with 1.439 billion monthly active users. While the exploit required the attacker to be a contact, the trust given to contacts within WeChat meant a compromised contact could further spread the worm. Tencent's swift action prevented potential widespread account takeovers, although the company has not published an advisory about the flaw.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~8 min · 6 stories · Sep 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security researchers at Calif developed and demonstrated a zero-click worm that could take over WeChat accounts on iPhone and Android via incoming calls from existing contacts. Tencent has since patched the exploit for all users, blocking the attack vector. This vulnerability was significant because it allowed account compromise without user interaction, affecting a platform with 1.439 billion monthly active users.