WeWorm zero-click WeChat-call worm on Android and iOS
Malware Activity
Summary
Hide ▲
Show ▼
The WeWorm malware was disclosed as a zero-click worm that spreads through WeChat calls on Android and iOS, creating a path to account takeover without user interaction. The tool can give an attacker full control of a targeted WeChat account and let the attacker act on the victim's behalf.
Related Happenings
WeChat zero-click incoming-call account takeover memory corruption flaw
Vulnerability
H score16
First: 08.09.2026 14:54
Last: 08.09.2026 14:54
Sources 1
How related:
They only explained that the flaw is a memory corruption issue in WeChat's voice-over-IP (VoIP) stack that relies on the privileges WeChat trusted contacts have when communicating with another user of the app.
About this happening:
Calif disclosed WeWorm, a zero-click worm that abuses a WeChat VoIP RCE reachable through an incoming call to take over WeChat accounts on iOS and Android....
WeChat zero-click incoming-call account takeover memory corruption flaw
VulnerabilityHow related: They only explained that the flaw is a memory corruption issue in WeChat's voice-over-IP (VoIP) stack that relies on the privileges WeChat trusted contacts have when communicating with another user of the app.
About this happening: Calif disclosed WeWorm, a zero-click worm that abuses a WeChat VoIP RCE reachable through an incoming call to take over WeChat accounts on iOS and Android....
Latest development: 09.09.2026 18:00
Calif disclosed WeWorm, a zero-click worm that exploits a WeChat VoIP RCE reachable through an incoming call to hijack iOS and Android phones and take over a victim's WeChat account. The disclosure report was dated September 8, and the researchers said they tested the tool on Google Pixel 10a and iPhone 17e devices.
Tencent WeChat security update for zero-click call flaw
Security Patch Release
H score16
First: 08.09.2026 14:54
Last: 08.09.2026 14:54
Sources 1
How related:
The Chinese firm later confirmed that exploiting the vulnerability could allow an attacker to perform remote command execution, and provided patched versions of the app on Android (8.0.77) and iOS (8.0.76).
About this happening:
WeChat had a zero-click incoming-call flaw that Calif said could be turned into remote command execution and account takeover on iOS and Android. Tencent relea...
Tencent WeChat security update for zero-click call flaw
Security Patch ReleaseHow related: The Chinese firm later confirmed that exploiting the vulnerability could allow an attacker to perform remote command execution, and provided patched versions of the app on Android (8.0.77) and iOS (8.0.76).
About this happening: WeChat had a zero-click incoming-call flaw that Calif said could be turned into remote command execution and account takeover on iOS and Android. Tencent relea...
SHub Reaper macOS infostealer variant
Malware Activity
H score23
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
Timeline
-
09.09.2026 18:00 2 articles · 2h ago
Calif discloses WeWorm zero-click worm abusing WeChat calls
Initial DisclosureCalif researchers disclosed WeWorm, a zero-click worm that uses a memory-corruption RCE in WeChat’s voice-over-IP stack reachable through an incoming call to take over targeted WeChat accounts on iOS and Android. They said they found the bug in July using LLMs and then built exploits for vulnerable WeChat apps before integrating them into WeWorm.
Show sources
- Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls — www.infosecurity-magazine.com — 09.09.2026 18:00
- Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls — www.infosecurity-magazine.com — 09.09.2026 18:00