← All articles

Researchers build a zero-click WeChat worm that spreads through voice calls

Security researchers built a zero-click worm that hijacks WeChat accounts through an incoming voice call on both iPhone and Android, without the target ever answering. The exploit fires during the ringing phase, before the user declines or picks up, abusing a memory-corruption flaw in WeChat's call-handling code to run commands on the device and take over the account. Because it can spread from a compromised contact to their contacts, it behaves like a worm. Notably, the researchers used AI to find the bug and write the exploit in about two days. Tencent patched it in late August and added a server-side mitigation, and saw no in-the-wild abuse before the fix.

Check
Make sure WeChat is updated to the patched version on all devices, since the fix landed in late August, and treat messaging apps with call features as a real remote attack surface.
Affected
WeChat users on iPhone and Android not updated before the late-August patch; a malicious incoming call could take over the account with no interaction, and the worm could spread to their contacts.
Fix
Keep messaging and calling apps updated promptly, prioritize patches for zero-click and call-handling flaws, and recognize that AI is shortening the time between a bug and a working exploit.