Breaking
SecurityConfirmed

WeChat worm exploited before calls answered

Tencent patches zero-click flaw that allowed account takeover via VoIP calls.

··1 hour ago·3 min read
black iphone 5 on yellow textile
Photo by Franck on Unsplash

Researchers at security firm Calif have demonstrated a zero-click exploit chain that could turn a WeChat call into a full account takeover before the recipient even answers. The attack, which they've named WeWorm, combines a memory corruption bug in WeChat's VoIP stack with AI-assisted development to produce what they describe as the first zero-click worm capable of spreading through calls on both iOS and Android.

The attack that spread itself

Calif's demonstration showed the exploit taking control of a victim's WeChat account within seconds, without the recipient needing to answer the call. From there, the compromised account would automatically call another contact and repeat the process, again without any user interaction.

Declining the call stopped infection, but answering it or letting it ring through did not. The researchers also noted that an attacker could retry when the recipient is away from the phone, making the attack harder to avoid if a call is missed.

Full control in seconds

In a statement, Calif said, "Exploitation takes only seconds, and gives us full control of the WeChat account. We can read and send messages, make calls, and act on the victim's behalf."

The vulnerability relies on the attacker being on the victim's friends list, but Calif argued this offers limited protection because a compromised account can be used to target its own trusted contacts, turning a single infection into a worm that spreads through social graphs.

Beyond the app

Calif says WeWorm could be chained with other vulnerabilities to escalate beyond the WeChat app and compromise the entire device. The team has not disclosed the full attack chain, but said in a statement: "Chained with other Android and iOS bugs we've reported and are helping fix, it can lead to full control of the device."

They also described a possible scenario where attackers "could exploit another app, gain root access using techniques like those in OEMpocalypse, take over the victim's WeChat app, and use it to attack you."

AI's role in discovery

Calif said it used AI to find the vulnerability and develop its first remote code execution (RCE) exploit in about two days. Tencent later confirmed the researchers' findings.

The researchers said they published their high-level findings to highlight how AI could make such capabilities available beyond "well-funded, sophisticated actors."

Patch timeline and disclosure

Tencent pushed fixes to address the attack on August 21. Despite this, Calif is withholding key details about the vulnerability, presumably to limit further exploitation. The team plans to present the full analysis of WeWorm at an upcoming conference.

Reaction from academics

Ryan Fedasiuk, an adjunct assistant professor in Georgetown University's Security Studies Program, described the discovery of WeWorm as "an extremely serious incident." He called on the US and China to maintain open communication and share information as AI increases the potential scale and severity of cyber threats.

What this means for users

For the 1.4 billion people who use WeChat monthly, this vulnerability is a stark reminder that even a trusted contact can become a vector for compromise. While Tencent has patched the issue, the existence of such a worm shows how quickly a single flaw can be turned into something that spreads automatically.

The fact that Calif was able to find and weaponize this bug in two days using AI tools suggests that other groups may soon have similar capabilities. This could raise the stakes for companies like Tencent to respond faster and for users to stay alert to unusual calls, even from friends.

The incident also underscores the importance of international cooperation in cybersecurity. As Fedasiuk pointed out, the US and China need to share information to keep pace with AI-driven threats that don't respect borders.

#wechat#zero-click#worm#tencent

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories