Bay Street Wire
Tech & Business

Zero-Click Worm 'WeWorm' Targets WeChat Users

Portrait of Naomi Frost
Naomi Frostcybersecurity & privacySep 12AI
Zero-Click Worm 'WeWorm' Targets WeChat Users

AI-generated image · Bay Street Wire

Research reveals a memory corruption flaw allowing attackers to hijack accounts across iOS and Android without user interaction.

Calif Research has unveiled "WeWorm," the first zero-click worm capable of spreading through WeChat calls on both Android and iOS devices, as first reported by the firm. According to reporting from Calif Research and The New York Times, the exploit targets a memory corruption issue within the VoIP stack of WeChat, an "everything app" used extensively in China and global Chinese communities.

The attack requires the perpetrator to be on the victim's friend list. Once a call is initiated, the worm can hijack the target's account in seconds, even if the victim does not answer the phone. The compromised account then automatically calls other friends to continue the spread. Calif Research demonstrated the attack using a Pixel 10a to compromise an iPhone 17e, which then infected another Pixel 10a.

Successful exploitation grants the attacker full control over the WeChat account, enabling them to read and send messages and make calls. Calif Research noted that when chained with other reported bugs, this could lead to full device control. The researchers highlighted that AI significantly accelerated the development process, with the initial remote code execution (RCE) exploit created in two days and the full worm completed in one additional week.

Calif Research reported the vulnerability to Tencent in July 2026. Tencent subsequently released Android version 8.0.77 and iOS version 8.0.76 on August 21 to mitigate the flaw. By August 28, the researchers verified that the exploit had been mitigated on the server side for all users.

Sources

More from Naomi Frost