https://calif.io/research/weworm

Security researchers have demonstrated a self-spreading worm capable of taking over WeChat accounts on both iPhone and Android devices through nothing more than an incoming phone call, with the target not needing to answer, decline or even touch their device for the attack to succeed. In a live demonstration, the researchers showed one compromised Android phone calling an iPhone and seizing control of its WeChat account while the phone was still ringing, after which the compromised iPhone then called a second Android device and repeated the process automatically. The only requirement is that the attacker already appears in the target’s WeChat contact list, a barrier described as relatively low given that once any contact’s account is taken over, the trust WeChat extends to known contacts works in the attacker’s favour rather than the user’s. Tencent, which reported 1.439 billion combined monthly active users across WeChat and Weixin as of June 2026, has since blocked the exploit at the server level, meaning users do not need to install an update for the fix to take effect, though running the latest version remains the safer option.

Once the exploit runs, researchers said the attacker gains full control of the WeChat account, with the ability to read and send messages, make calls and act as the account owner. For a significant portion of WeChat’s user base, the stakes extend well beyond private messaging given the app’s integration with payments, official accounts and mini programs. The vulnerability was reported in July and confirmed on 28 August that the exploit had been blocked on Tencent’s servers following the release of updated app versions on 21 August. However, the company has not published a formal security advisory, listed a CVE identifier for the flaw or clarified whether the underlying vulnerability has been fully patched or merely had the specific exploit blocked.

Adding a notable dimension to the story, the researchers disclosed that the vulnerability was discovered with the assistance of AI, which the firm had guided using a purpose-built set of skills designed to explore and identify potential attack surfaces in messaging apps. From initial discovery to a working exploit capable of running code on the device took roughly two days, with the full worm demonstration completed within a week. The researchers have withheld full technical details pending a formal conference presentation, meaning no indicators are currently available that defenders could search for or that affected users could use to determine whether they were targeted.

Discover more from Edwin Kwan

Subscribe now to keep reading and get access to the full archive.

Continue reading