# WeChat Vulnerability Exploited by Zero-Click Worm on Mobile Devices

*Published September 11, 2026*
*Source: [https://www.infosecurity-magazine.com/news/wechat-zeroclick-worm-hijack/](https://www.infosecurity-magazine.com/news/wechat-zeroclick-worm-hijack/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/wechat-vulnerability-exploited-by-zero-click-worm-on-mobile-devices) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Researchers at Calif, a cybersecurity startup in Palo Alto, have developed a sophisticated tool that can hack into both Android and iOS phones through an incoming call on WeChat. Named WeWorm, this tool takes advantage of remote code execution vulnerabilities in WeChat, a widely used app in China with features ranging from messaging to financial transactions. This marks the first instance of a zero-click worm spreading through WeChat calls on both operating systems. 

The vulnerability, identified by Calif researchers in July, was found using a mix of large language models, though specific details about these models or the vulnerability itself were not disclosed. The flaw is a memory corruption issue within WeChat’s voice-over-IP stack, affecting the privileges of trusted contacts. Despite an initial ban after reporting the flaw to Tencent, WeChat's developer, the company has since confirmed the issue and released patched versions for Android and iOS users. 

The WeWorm tool offers attackers full control over a WeChat account, enabling them to send messages, make calls, and act on behalf of the victim without any interaction needed from the victim. Even if the victim declines the call, the attacker can retry later. Although the exploit requires the attacker to be a friend of the victim on WeChat, this is not a significant barrier since attackers can first compromise mutual friends. If combined with other vulnerabilities, WeWorm could potentially allow full control of the device. The researchers highlighted the role of AI in rapidly developing this tool, emphasizing that what once took a large team months can now be achieved much faster with AI assistance.
