Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: zero-click (2 articles)Clear

Researchers build a zero-click WeChat worm that spreads through voice calls

Security researchers built a zero-click worm that hijacks WeChat accounts through an incoming voice call on both iPhone and Android, without the target ever answering. The exploit fires during the ringing phase, before the user declines or picks up, abusing a memory-corruption flaw in WeChat's call-handling code to run commands on the device and take over the account. Because it can spread from a compromised contact to their contacts, it behaves like a worm. Notably, the researchers used AI to find the bug and write the exploit in about two days. Tencent patched it in late August and added a server-side mitigation, and saw no in-the-wild abuse before the fix.

Check
Make sure WeChat is updated to the patched version on all devices, since the fix landed in late August, and treat messaging apps with call features as a real remote attack surface.
Affected
WeChat users on iPhone and Android not updated before the late-August patch; a malicious incoming call could take over the account with no interaction, and the worm could spread to their contacts.
Fix
Keep messaging and calling apps updated promptly, prioritize patches for zero-click and call-handling flaws, and recognize that AI is shortening the time between a bug and a working exploit.

Forenser documents zero-click WhatsApp account takeover on iPhone iOS 16 - parallel session, no linked devices, used for wire-transfer scams

Italian digital forensics firm Forenser has documented an active zero-click WhatsApp account-takeover campaign targeting iPhone users on iOS 16. Victims (iPhone 8 through 14) reported messages requesting wire transfers being sent from their accounts to recent contacts, with no Linked Devices entries and no QR code interaction. Unified-log analysis shows continuous WhatsApp session-resync events - the signature of two endpoints competing for the same account, with the attacker bypassing the standard linked-device registration. The campaign exploits known iOS 16 vulnerabilities. Affected users do not see archived chats, suggesting the attacker has only recent-chat access. Forenser recommends upgrading to iOS 17 or later.

Check
Search MDM data for iPhones still on iOS 16. Check WhatsApp Linked Devices on possibly-affected handsets (will appear empty). Pull unified logs for continuous resync events if Forenser's IoCs apply.
Affected
iPhone users on iOS 16 (iPhone 8 through 14, including X, XR, XS, 11, SE, 12, 13). WhatsApp on these devices is susceptible to a zero-click parallel-session takeover.
Fix
Upgrade affected iPhones to iOS 17 or later immediately. Sign out and re-register WhatsApp accounts after the upgrade. Educate users to verify suspicious wire-transfer requests via a second channel.