Security firm Calif developed a worm capable of taking over WeChat accounts through an incoming call. The exploit worked on both iPhone and Android devices, requiring no action from the recipient, such as answering or touching the phone. The only prerequisite was that the attacker needed to be an existing WeChat contact of the target.
Calif demonstrated the worm's spread by compromising an iPhone from an Android phone, then using the compromised iPhone to take over a second Android phone. Once exploited, the attacker gained full control of the WeChat account, enabling them to read and send messages, make calls, and act as the account owner. The exploit did not grant control over the phone itself, but WeChat's extensive features, including payments and mini-programs, made account compromise significant.
Calif reported the flaw to Tencent in July. Tencent subsequently released updates (version 8.0.77 for Android and 8.0.76 for iOS) on August 21, which mitigated the bug. By August 28, Calif confirmed that the exploit was also blocked on Tencent's servers, effectively patching the vulnerability for all users. No attacks leveraging this specific flaw were reported in the wild.
The fix addresses a critical zero-click vulnerability on a platform with 1.439 billion monthly active users. While the exploit required the attacker to be a contact, the trust given to contacts within WeChat meant a compromised contact could further spread the worm. Tencent's swift action prevented potential widespread account takeovers, although the company has not published an advisory about the flaw.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researchers at Calif developed and demonstrated a zero-click worm that could take over WeChat accounts on iPhone and Android via incoming calls from existing contacts. Tencent has since patched the exploit for all users, blocking the attack vector. This vulnerability was significant because it allowed account compromise without user interaction, affecting a platform with 1.439 billion monthly active users.