As cited
Copy frozen at (site build).
vulnerabilities
WeChat worm could pwn a friend before they even answered the call
Researchers at Calif discovered WeWorm, a zero-click vulnerability in WeChat's VoIP stack that enables remote code execution (RCE) and account takeover through incoming calls. The flaw, which affects both iOS and Android, allows a trusted contact to compromise a victim's account in seconds without requiring the user to answer, then propagates to other contacts automatically. Tencent released patches on August 21, 2026, though Calif is withholding technical details pending a full conference presentation.
Why it matters: WeChat users with 1.4 billion monthly active users face account compromise and message interception from any trusted contact; defenders should ensure updates are deployed and educate users that missed calls from friends may still pose infection risk.
- Source published
- First seen by Cybersecurity Tracker