WeWorm turns a WeChat call into a zero-click account worm
Calif Research on 8 September 2026 demoed WeWorm, a WeChat VoIP zero-click account takeover on iOS and Android. Tencent shipped Android 8.0.77 and iOS 8.0.76 on 21 August, and Calif confirmed a server-side block on 28 August. Combined WeChat and Weixin monthly actives were 1.439 billion as of 30 June 2026.

Calif Research on 8 September 2026 published a demo of WeWorm, which it calls the first zero-click worm that spreads through WeChat calls on both iOS and Android. In the lab chain, a Pixel 10a called an iPhone 17e, took over WeChat while the phone was still ringing, then used that iPhone to call another Pixel 10a the same way.
This is a security research disclosure and a lab demo of a now-mitigated WeChat VoIP account-takeover worm. It is not a claim of in-the-wild mass exploitation, and Tencent has published no dedicated CVE advisory in the sources covering the drop.
The victim does not need to answer or touch the phone. Answering still succeeds, with silence on the line. Declining stops that attempt, though Calif says the attacker can retry later. The attacker must already be on the victim's WeChat friend or contact list, or must compromise a contact first.
The exploit gives full control of the WeChat account, including reading and sending messages, making calls, and acting as the user. Alone it does not give full device control. Calif says chaining with other bugs can escalate.
Working with AI, Calif says it found the bug and wrote the first remote-code-execution exploit in about two days. Building the worm took about one more week. The firm reported the bug to Tencent in July.
Calif's own timeline says Tencent published Android 8.0.77 and iOS 8.0.76 on 21 August 2026, and that Calif confirmed a server-side block on 28 August. Calif says the exploit has been mitigated for all users.
The Hacker News reports Tencent's release notes framed those builds as bug fixes, and that Calif would not say whether the underlying flaw is fully fixed versus blocked. Calif reports no known attacks using its exploit. THN, citing Tencent's second-quarter results, puts combined WeChat and Weixin monthly active users at 1.439 billion as of 30 June 2026.

Worm and mobile-account risk this week also includes ScreenConnect guest file transfer, Microsoft's September 2026 Patch Tuesday, Claude Code auto-mode prompt injection, and SonicWall SMA1000 zero-days.
If your users or staff run WeChat, treat current client builds at or above Android 8.0.77 and iOS 8.0.76 plus Tencent's server-side block as the live mitigation, and assume a compromised contact can still be the delivery path for the next VoIP bug.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free