TL;DR
Security firm Calif built WeWorm, the first zero-click worm to propagate through WeChat voice calls on both iOS and Android. A single unanswered call can hijack the victim’s account within seconds. Tencent has patched the underlying memory corruption bug for all users.
Why This Matters
WeChat is the dominant messaging and payments platform for over a billion users in China and across Chinese communities worldwide. A worm that spreads via voice calls – with no tap, swipe, or answer required – represents a threat category most users cannot defend against alone.
Calif warns that the scale is staggering. As the researchers put it, “if exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide.” The New York Times reported that experts believe a live version could have reached hundreds of millions of accounts within hours.
The threat is not theoretical. Calif’s team – working with AI assistance – found the bug and wrote the first remote code execution (RCE) exploit in roughly two days. Building the full worm took one additional week. That speed signals a shift: attack development timelines are shrinking fast.
How WeWorm Works
The root cause is a memory corruption flaw in WeChat’s VoIP call-handling stack. Calif withholds the full technical details for now, planning to present them at an upcoming conference. However, the attack mechanism is clear from their published WeWorm research.
An attacker places a WeChat call to a target. The exploit fires while the phone is still ringing. “The victim does not need to answer the call, or interact with their phone at all,” the Calif advisory states. Declining the call blocks that attempt, but the attacker can simply retry – for example, while the target sleeps.
Once the exploit succeeds, the attacker gains full control of the WeChat account. They can read and send messages, place calls, and act as the victim. The compromised account then calls the victim’s contacts, repeating the cycle automatically.
Chained with other Android and iOS bugs that Calif is helping fix, the exploit could escalate to full device control. However, the WeWorm bug alone does not guarantee full device takeover.
The Friend-List Barrier
The attack requires the attacker to appear on the victim’s WeChat friend list. That sounds like a meaningful constraint. In practice, it is not.
An attacker can first compromise one of your contacts and then use that trusted account to reach you. WeChat, like many messaging apps, grants trusted contacts elevated privileges. That design choice turns compromised contacts into stepping stones through entire social networks.
Affected Versions and Patch Status
Tencent patched the server-side issue for all users on August 28, 2026, before Calif’s public disclosure. Tencent also released updated app versions – Android 8.0.77 and iOS 8.0.76 – on August 21, which mitigated the client-side exploit. On September 4, Tencent confirmed that the vulnerability could be used for remote command execution.
No CVE identifier has been publicly assigned to this vulnerability. Calif states it is withholding technical details pending a conference presentation. No exploitation in the wild has been confirmed beyond Calif’s own proof-of-concept research.
Disclosure Timeline
Calif’s AI discovered the bug sometime in July 2026. The engineering team learned of it on July 23 and reported it to Tencent on July 24. Calif completed the Android RCE exploit on July 30 and the iOS exploit on August 2. The polished worm demo was ready on August 11. Tencent published patched app versions on August 21 and confirmed server-side mitigation on August 28.
What Users Should Do
Update WeChat immediately to Android 8.0.77 or iOS 8.0.76 or later. The server-side fix means the specific WeWorm exploit is already blocked, but updating the app closes any remaining client-side exposure. Review your WeChat contact list and remove unfamiliar connections. Stay alert for unexpected incoming calls from known contacts, which could signal a compromised account attempting to propagate further.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!