Find notable cyber news and cases, enriched with sources, timelines, and signals.

WeChat zero-click incoming-call account takeover security flaw

Vulnerability
First reported
Last updated
Happening score
H score 16
1 unique sources, 1 articles

Summary

Hide ▲

Calif demonstrated a zero-click incoming-call flaw in WeChat that let an attacker seize accounts on iPhone and Android, creating account-takeover risk without user interaction. The worm spread across three test phones and required the caller to already be on the target's contact list. Once it ran, the attacker could read and send messages, place calls, and act as the account owner. Tencent later said it had mitigated the exploit for all users.

Timeline

  1. 08.09.2026 14:54 1 articles · 21h ago

    Calif identifies a WeChat zero-click incoming-call bug

    Technical Analysis Update

    Calif's engineering team knew of the WeChat flaw on 23 July 2026, beginning work on a zero-click incoming-call path that could let a caller already in the target's contacts take over a WeChat account without any user interaction.

    Show sources
  2. 08.09.2026 14:54 1 articles · 21h ago

    Calif demonstrates a WeChat worm spreading across three test phones

    Exploitation Observed

    On 11 August 2026, Calif demonstrated a worm that took over a WeChat account on an iPhone while the phone was still ringing, then used that compromised account to call a second Android phone and take control of it, spreading across three test phones.

    Show sources
  3. 08.09.2026 14:54 2 articles · 21h ago

    Calif confirms Tencent server-side blocking of the WeChat exploit

    Mitigation Patch Update

    On 28 August 2026, Calif confirmed that Tencent had blocked the exploit on its servers for all WeChat users, so the mitigation did not require any user action.

    Show sources