WeChat zero-click incoming-call account takeover security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Calif demonstrated a zero-click incoming-call flaw in WeChat that let an attacker seize accounts on iPhone and Android, creating account-takeover risk without user interaction. The worm spread across three test phones and required the caller to already be on the target's contact list. Once it ran, the attacker could read and send messages, place calls, and act as the account owner. Tencent later said it had mitigated the exploit for all users.
Timeline
-
08.09.2026 14:54 1 articles · 21h ago
Calif identifies a WeChat zero-click incoming-call bug
Technical Analysis UpdateCalif's engineering team knew of the WeChat flaw on 23 July 2026, beginning work on a zero-click incoming-call path that could let a caller already in the target's contacts take over a WeChat account without any user interaction.
Show sources
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls — thehackernews.com — 08.09.2026 14:54
-
08.09.2026 14:54 1 articles · 21h ago
Calif finishes the first Android exploit for the WeChat flaw
Technical Analysis UpdateOn 30 July 2026, Calif finished the first Android exploit for the WeChat zero-click flaw, advancing a proof of concept that could run code on the phone.
Show sources
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls — thehackernews.com — 08.09.2026 14:54
-
08.09.2026 14:54 1 articles · 21h ago
Calif demonstrates a WeChat worm spreading across three test phones
Exploitation ObservedOn 11 August 2026, Calif demonstrated a worm that took over a WeChat account on an iPhone while the phone was still ringing, then used that compromised account to call a second Android phone and take control of it, spreading across three test phones.
Show sources
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls — thehackernews.com — 08.09.2026 14:54
-
08.09.2026 14:54 1 articles · 21h ago
Tencent releases WeChat updates that mitigated the exploit
Mitigation Patch UpdateTencent released WeChat 8.0.77 for Android and 8.0.76 for iOS on 21 August 2026, and Calif said those releases mitigated the bug for WeChat users.
Show sources
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls — thehackernews.com — 08.09.2026 14:54
-
08.09.2026 14:54 2 articles · 21h ago
Calif confirms Tencent server-side blocking of the WeChat exploit
Mitigation Patch UpdateOn 28 August 2026, Calif confirmed that Tencent had blocked the exploit on its servers for all WeChat users, so the mitigation did not require any user action.
Show sources
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls — thehackernews.com — 08.09.2026 14:54
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls — thehackernews.com — 08.09.2026 14:54