Security researchers at Calif have successfully demonstrated a zero-click worm targeting WeChat, capable of compromising user accounts via incoming calls without any user interaction. The vulnerability allowed an attacker, who must be on the victim's contact list, to take control of a WeChat account simply by initiating a call. The target did not need to answer, and the attack could proceed while the phone was still ringing, potentially spreading further by exploiting the trust within contact lists. Calif reported this flaw to Tencent in July. The company responded swiftly, blocking the exploit for all users by August. Although no real-world attacks were reported, this incident underscores the risks associated with zero-click vulnerabilities. WeChat, which functions beyond a simple chat app by integrating services like payments and mini-programs, has a massive user base, with Tencent reporting 1.439 billion monthly active users as of June 2026. Tencent's latest updates for Android and iOS, versions 8.0.77 and 8.0.76 respectively, have mitigated the vulnerability. Calif confirmed that Tencent's servers now block the exploit, offering enhanced security without requiring users to take action. However, Tencent has not issued a public advisory or detailed the fix's scope. Calif has withheld technical details, intending to present them at an upcoming conference, leaving some uncertainty about which versions were susceptible. Despite this, users are encouraged to update to the latest app versions to ensure optimal security.
WeChat Zero-Click Vulnerability: A Silent Threat Neutralized
Researchers built a WeChat zero-click worm that takes over accounts via incoming calls without user interaction, spreading across phones.
Executive Summary
Researchers at Calif discovered a zero-click worm that could compromise WeChat accounts via incoming calls, prompting Tencent to block the exploit. Although no attacks were reported, the vulnerability highlighted the risks of zero-click exploits in widely used applications.
Actionable Insights
- Ensure all devices have the latest WeChat version installed.
- Verify contact lists and remove any suspicious or unknown entries.
- Monitor WeChat activity for any unusual behavior or unauthorized access.
- Educate users about the risks of zero-click vulnerabilities.
- Stay informed on updates from Tencent regarding potential security advisories.
Original source
thehackernews.com

