Ethical Hacking News
WeChat has been hit with a zero-click worm that can take over accounts on iPhone and Android devices via incoming calls. The worm, discovered by security firm Calif, has left users wondering about the safety of their WeChat accounts. With this vulnerability, users are not only vulnerable to account takeover but also to potential identity theft and financial loss. The company has since blocked the exploit for all users, but users are advised to run a current version of WeChat to stay safe.
Summary: A zero-click worm has been discovered in WeChat that can take over accounts on iPhone and Android devices via incoming calls. The worm, discovered by Calif, has raised concerns about mobile security and the need for users to stay updated with the latest security patches.
WeChat has been hit with a zero-click worm that can take over accounts on iPhone and Android devices via incoming calls. The worm was built using artificial intelligence and can spread among phones without requiring any action from the target. The worm can take control of a WeChat account, read and send messages, make calls, and act as the account's owner. The bug was discovered by Calif and reported to Tencent, which has since blocked the exploit for all users. Users are advised to run a current version of WeChat to stay safe, and users should remain vigilant and keep their accounts secure.
WeChat, one of the most popular social media and messaging apps in the world, has been hit with a zero-click worm that can take over accounts on iPhone and Android devices via incoming calls. This vulnerability, discovered by security firm Calif, has left users wondering about the safety of their WeChat accounts and the ease with which hackers can exploit them.
According to Calif, the worm was built using artificial intelligence (AI) and can spread among three test phones without requiring any action from the target. The caller must already be on the target's WeChat contact list, which is not much of a barrier, as once a contact is compromised, the extra trust WeChat gives to contacts works for the attacker rather than the user.
The worm is capable of taking control of a WeChat account and reading and sending messages, making calls, and acting as the account's owner. This means that users are not only vulnerable to account takeover but also to potential identity theft and financial loss.
Researchers at Calif worked with AI to find the bug and write the first exploit that could run code on the phone in about two days. Building the worm took another week, and the team's timeline shows that they knew of the bug on July 23, finished the first Android exploit on July 30, and demoed the worm on August 11.
Calif reported the flaw to Tencent in July, and the company has since blocked the exploit for all users. However, users are still at risk, especially those who are using outdated versions of WeChat. The company has released version 8.0.77 for Android and 8.0.76 for iOS on August 21, but users are advised to run a current version to stay safe.
The vulnerability was discovered after Calif worked with AI to identify a flaw in WeChat's security. The company has since taken steps to mitigate the bug, but users should remain vigilant and keep their WeChat accounts secure.
The discovery of this zero-click worm highlights the importance of mobile security and the need for users to stay updated with the latest security patches. As hackers continue to find new vulnerabilities in popular apps, it is essential for users to be aware of the potential risks and take steps to protect themselves.
Related Information:
https://www.ethicalhackingnews.com/articles/WeChat-Zero-Click-Worm-A-Lurking-Threat-to-Mobile-Security-ehn.shtml
https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
Published: Tue Sep 8 08:44:10 2026 by llama3.2 3B Q4_K_M