- California-based researchers discovered a zero-click VoIP vulnerability that enables account takeover through incoming calls
- “WeWorm” propagates simply by ringing the target device, requiring no action from the victim
- Tencent issued patches for Android version 8.0.77 and iOS version 8.0.76, with no known exploitation detected in the wild
Security researchers have uncovered a zero-click vulnerability in WeChat that allows malicious actors to seize control of user accounts across both Android and iOS platforms. The most critical aspect of this flaw is that victims do not need to interact with the device in any way to be compromised.
Often referred to as a “super-app,” WeChat serves approximately 1.4 billion users, particularly in China. Originally designed as a messaging platform for text, voice, and video communication, it has evolved into a comprehensive social network and payment system capable of handling financial transactions, food orders, and government services.
Researchers from California have disclosed a memory corruption issue within WeChat’s VoIP stack. While the technical details remain undisclosed for an upcoming conference demonstration, the team constructed a worm named WeWorm. This malware can seize control of target WeChat accounts and propagate via the app’s voice calling feature.
A phone call is all it takes
The attack mechanism is remarkably straightforward. An attacker initiates a WeChat call to a contact within their list—a necessary prerequisite for the exploit. This can be executed from either an Android or iOS device, targeting any user regardless of their phone model or operating system. The moment the phone begins to ring, WeWorm executes its payload, infiltrating the victim’s device.
Victims do not even need to answer the call; the ringing alone is sufficient to trigger the attack. If they do answer, they will hear nothing but silence, yet the worm continues its operation unchecked. If they decline the call, the attack halts momentarily, but this offers negligible protection, as the attacker can simply call again while the victim is asleep or otherwise away from their device.
Within seconds, the attacker gains full access to the victim’s WeChat account, including their messages, contact lists, and virtually any other data stored within the application. While the ability to transfer money and make payments through WeChat Pay is particularly concerning, the platform’s additional authentication and risk control mechanisms serve as a secondary safeguard against unauthorized financial transactions.
Currently, there is no evidence that this vulnerability has been exploited in the wild. However, the broader concern is that this is not the first zero-click flaw discovered in modern smartphones, and it is unlikely to be the last.

Tencent’s response
California researchers responsibly disclosed their findings to WeChat’s parent company, Tencent, which responded with a patch. Android version 8.0.77 and iOS version 8.0.76 reportedly resolve the issue. Tencent did not provide specific details in its patch notes, merely stating that the update included “bug fixes.” However, in a statement shared with The Hacker News, the company confirmed that the exploit has been “mitigated for all users” via a server-side fix, meaning users do not need to install a new version unless the patch applies to their device.
It is worth noting that WeChat also operates on HarmonyOS, Windows, Mac, and Linux. However, the California researchers appear not to have tested those platforms, and Tencent did not include them in its current patch. The team indicated they would investigate this vulnerability across other products as well.
“This specific WeChat bug is one instance of the many unconventional attack surfaces present across modern messaging apps,” the researchers stated. “We are conducting further research into attack surfaces across other applications while collaborating with developers on attack surface reduction. This will likely require an industry-wide effort, as it partly depends on platform owners. Once this work progresses further, we will share our findings, including the technical details of this WeChat bug.”
Also Read
- Flawed Lab Measurement Method Overstates CRISPR’s RNA Knockdown Efficiency
- Listen Labs Cancels $1.5 Billion Funding Round as Salesforce Acquisition Talks Stagnate
- Understanding the Distinction Between Apple Wallet and Apple Pay
- Multiple Threat Actors Exploit BlueMoon Kit Targeting Chrome and Windows Flaws


