Skip to main content
Emerging ThreatsMalware & Ransomware

WeChat Zero-Click Flaw Exploited to Hijack Accounts via Incoming Calls

Two phones on a plain surface, one still and one recently ringing.

"Calif has mitigated our exploit for all users," the security firm wrote, describing a zero‑click worm that — in lab tests — took over WeChat accounts on both iPhone and Android simply by placing an incoming call.

The Calif demonstration: a three‑phone worm

Researchers at Calif built and demonstrated a worm that spreads between WeChat accounts using only incoming calls. In the firm’s demo one Android phone called an iPhone and took control of its WeChat account while the iPhone was still ringing; the compromised iPhone then called a second Android phone and seized that account the same way. Calif reported the flaw to Tencent in July and said Tencent has since blocked the exploit for all users.

How the zero‑click call behaves

The exploit is a zero‑click attack: the person being called does not have to answer or touch the phone for the exploit to run. Calif said answering does not stop the attack — a recipient who picks up may hear nothing while the exploit still succeeds — whereas declining the call ends that attempt, though an attacker can call again later. Importantly, the caller must already be on the target’s WeChat contact list, which Calif said lowers the barrier to propagation because control of one contact can be used to build trust for subsequent calls.

What control the attacker gains — and what they do not

Calif reported that once the exploit runs, an attacker gains full control of the WeChat account itself: they can read and send messages, make calls, and act as the account’s owner. Calif was explicit that the exploit, on its own, does not give control of the underlying phone hardware or operating system.

Tencent’s releases, mitigation timeline, and disclosure status

Tencent released WeChat version 8.0.77 for Android and 8.0.76 for iOS on 21 August, according to its release log; Calif said those releases mitigated the bug and that on 28 August it confirmed the exploit was blocked on Tencent’s servers as well. Calif also said the server‑side block means the fix does not require individual users to install an update, though running a current client remains the safer choice. As of 8 September, the App Store listing showed 8.0.76 as the current iOS version.

Tencent has published no public advisory about the flaw; the iOS release notes and App Store entry describe the update as only "bug fixes." Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent’s security response site, which lists its latest announcement as April 2022. Calif is withholding technical details and plans to present a full analysis at a conference; it has not published signatures or indicators defenders could search for. The Hacker News has contacted Tencent and Calif for comment.

Calif’s development timeline and use of AI

Calif reported that it worked with AI to find the bug and to write the first exploit that could run code on a phone in about two days, and that building the worm took another week. Its public timeline gives longer gaps: the engineering team knew of the bug on 23 July, the first Android exploit was finished on 30 July, and the worm demo occurred on 11 August. The firm reported the flaw to Tencent in July.

What this means for end users, security teams, and adversaries

  • End users: Calif said users cannot tell whether they were called and that Tencent has not published which WeChat versions were affected, so individuals cannot verify past exposure by checking their client version for July or August. Calif also noted Tencent ships clients for HarmonyOS, Windows, Mac and Linux on separate schedules; neither company has said whether those clients were affected.
  • Security teams and technologists: Calif confirmed it has not released technical indicators and plans to withhold details until its conference presentation; teams should therefore rely on Tencent’s server‑side block and the app updates while monitoring for any official advisories or a CVE assignment.
  • Adversaries and threat actors: The demonstration shows a propagation vector that depends on contact‑list trust: once an account is compromised, it can be used to place trusted calls that propagate the worm to other contacts, according to Calif’s analysis.

No attacks exploiting the flaw have been reported, and Calif does not say there were any. Tencent reported combined monthly active users for WeChat and Weixin at 1.439 billion as of 30 June 2026 in its second‑quarter results — a reminder that account compromise on a widely used messaging platform carries broad potential impact even if no real‑world exploitation has been observed so far.

Calif’s public posture — confirming a server‑side block while withholding exploit details pending a conference presentation — leaves a narrow window for verification: users are told the risk has been neutralized at scale, but cannot independently search logs or signatures to confirm whether a past incoming call triggered compromise. Whether Tencent will publish a formal advisory, submit a CVE, or clarify the status of non‑mobile clients remains to be seen.

Read the original Hacker News report