CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6615

As cited

Copy frozen at (site build).

vulnerabilities

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

Researchers at Calif discovered a zero-click worm targeting WeChat that compromises accounts through incoming calls without user interaction, requiring only that the caller be an existing contact. The worm was demonstrated spreading across three test devices on both iOS and Android. Tencent received the disclosure in July and has since taken action.

Why it matters: WeChat users on iPhone and Android face account takeover risk from any contact initiating a call; patching status and user mitigation options require immediate clarity from Tencent.

VendorsAppleGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary