Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Guardian view on English schools: teachers and pupils should be proud of bucking a downward trend | Editorial

    September 9, 2026

    The Guardian view on Britain’s new Middle East policy: an unlawful occupation must carry a price | Editorial

    September 9, 2026

    Hackers are stealing Claude tokens from subscribers

    September 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Guardian view on English schools: teachers and pupils should be proud of bucking a downward trend | Editorial
    • The Guardian view on Britain’s new Middle East policy: an unlawful occupation must carry a price | Editorial
    • Hackers are stealing Claude tokens from subscribers
    • Funding grants for new research into AI and teen development
    • WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
    • Visa Expands Stablecoin Strategy with Blockchain Lending
    • Many People Aren’t Connecting the Dots Between Climate Change and Extreme Weather
    • China: How the PLA Officer Corps Works
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 9, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 08, 2026Vulnerability / Mobile Security

    Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones.

    The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since blocked the exploit for all users.

    No attacks using the flaw have been reported, and Calif does not say there were any. Attacks that require no action from the target, known as zero-click attacks, are not new. Last year, WhatsApp patched a flaw it said may have been used in targeted attacks.

    Answering the call does not stop the attack. Calif said a person who picks up hears nothing and the exploit still works. Declining the call ends that attempt, but the attacker can call again later, for example while the target is asleep.

    Cybersecurity

    The caller has to be on the target’s WeChat contact list. Calif said that is not much of a barrier, because once a contact is taken over, the extra trust WeChat gives to contacts works for the attacker rather than the user.

    That handover is the part the demo shows. One Android phone called an iPhone and took over its WeChat while the phone was still ringing. The compromised iPhone then called a second Android phone and took control of it the same way.

    Calif’s post describes routes an attacker could use rather than ones it tested. Once the exploit runs, the researchers said, the attacker has full control of the WeChat account and can read and send messages, make calls, and act as the account’s owner. On its own, it does not give control of the phone itself.

    For many users, that account is not only a chat app. WeChat’s App Store listing covers payments, official accounts and mini programs inside the app. Tencent put the combined monthly active users of WeChat and Weixin at 1.439 billion as of 30 June 2026 in its second-quarter results.

    Tencent released version 8.0.77 for Android and 8.0.76 for iOS on 21 August, according to its own release log. Calif said those releases mitigated the bug and that, on 28 August, it confirmed the exploit was blocked on Tencent’s servers as well.

    The researchers said Tencent has “mitigated our exploit for all users.” Asked whether the underlying flaw had also been fixed, Calif told The Hacker News it could not comment. Tencent has published no advisory about the flaw, and its release notes for the iOS version and its App Store entry describe the update as only bug fixes.

    According to Calif, the block runs on Tencent’s servers, so it does not require users to install anything. Running a current version is still the safer choice, and on 8 September that listing showed 8.0.76, released on 21 August, as the current version.

    Calif told The Hacker News it tested the exploit against WeChat 8.0.76 for Android and 8.0.75 for iOS, in each case the version numbered one below the release Tencent shipped on 21 August. It said the tests ran on iOS 26.6 and some older Android versions. Neither company has published a full list of affected versions, so a user on a different build cannot tell whether it was vulnerable.

    Tencent also ships WeChat clients for HarmonyOS, Windows, Mac and Linux on their own release schedules. Calif declined in the same reply to say whether it had tested any of them, and Tencent has not addressed them.

    Cybersecurity

    Calif is holding back the technical details and plans to present the full analysis at a conference. It has not published anything a defender could search for, and there is no way for a user to tell whether they were called.

    Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent’s security response site, which lists the latest announcement as April 2022. The Hacker News has contacted Tencent for comment.

    Calif said it worked with AI to find the bug and write the first exploit that could run code on the phone in about two days. Building the worm took another week, it said.

    Calif told The Hacker News it had designed a set of skills that guide an AI in exploring and identifying potential attack surfaces in messaging apps, and that the AI discovered this flaw using them.

    Its own timeline gives longer gaps. Its engineering team knew of the bug on 23 July, the first Android exploit was finished on 30 July, and the worm demo on 11 August. The post does not say whether the shorter figures count only working time.

    Accounts Android Calls Incoming iPhone WeChat Worm zeroclick
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

    ChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another Account

    Microsoft releases Windows 10 KB5122878 extended security update

    Here’s Samsung’s Advice for Apple and Its Upcoming Folding iPhone

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Guardian view on English schools: teachers and pupils should be proud of bucking a downward trend | Editorial

    September 9, 2026

    The Guardian view on Britain’s new Middle East policy: an unlawful occupation must carry a price | Editorial

    September 9, 2026

    Hackers are stealing Claude tokens from subscribers

    September 9, 2026

    Funding grants for new research into AI and teen development

    September 9, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Guardian view on English schools: teachers and pupils should be proud of bucking a downward trend | Editorial

    September 9, 2026

    The Guardian view on Britain’s new Middle East policy: an unlawful occupation must carry a price | Editorial

    September 9, 2026

    Hackers are stealing Claude tokens from subscribers

    September 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.