VMTech
Discuss a project

Tencent blocks WeChat zero-click account takeover worm

Tencent blocks WeChat zero-click account takeover worm

WeChat flaw allowed account takeover through incoming calls

Security firm Calif has demonstrated a worm that could take over WeChat accounts on both iPhone and Android through an incoming call. The recipient did not need to answer the call or interact with the device, while the caller needed to be on the target's WeChat contact list.

Calif reported the issue to Tencent in July. The researchers said Tencent has since mitigated the exploit for all users, including through a server-side block confirmed on 28 August. Calif and Tencent have not reported attacks exploiting the flaw in the wild.

The demonstration involved three test phones. An Android device called an iPhone and took over its WeChat account while the phone was ringing. The compromised iPhone then called a second Android device and took control of that account in the same way.

Account access, rather than device control

Once the exploit ran, Calif said an attacker could fully control the victim's WeChat account: reading and sending messages, placing calls and acting as the account owner. The issue did not itself provide control of the underlying phone.

That distinction still leaves material exposure for users and organisations that rely on WeChat beyond messaging. Its App Store listing includes payments, official accounts and mini programs. Tencent reported 1.439 billion combined monthly active users for WeChat and Weixin as of 30 June 2026.

The contact prerequisite was central to the worm's spread. Calif said WeChat's additional trust in contacts could work in an attacker's favour after an account had been compromised. Answering an incoming call did not halt the exploit in Calif's testing; declining it ended that attempt, although a caller could try again later.

Mitigation status and remaining uncertainty

Tencent released WeChat 8.0.77 for Android and 8.0.76 for iOS on 21 August. Calif said those releases mitigated the bug. Tencent's iOS release notes and App Store entry described the update only as bug fixes, while Tencent has not published a security advisory for the issue.

Calif said the server-side protection does not require users to install anything, but running a current client remains the safer course. Neither company has identified affected versions, so users cannot determine whether a version they used in July or August was vulnerable.

The researchers are withholding technical details pending a conference presentation. There is no published CVE identifier, no disclosed indicator defenders can search for, and no stated way for a user to establish whether they received a malicious call. Tencent and Calif also have not said whether WeChat clients for HarmonyOS, Windows, Mac or Linux were affected.

For businesses using WeChat for customer contact, payments or internal communication, the practical implication is to maintain current clients, control who can become trusted contacts and prepare account-recovery procedures that do not depend on a compromised account.

#wechat#mobilesecurity#zeroclick#accountsecurity
Open analytics
On the site 0 views
min read 3 08.09.2026
Instagram

Tencent blocks WeChat zero-click account takeover worm

Open the post on Instagram ↗