A voice call alone can now put a messaging account in an attacker’s hands, with no answer, tap, or install required from the victim. A demo moved the takeover from an Android phone to an iPhone and on to a second Android device.
The work comes from the security firm Calif, which named the exploit WeWorm and describes it as the first self-propagating account theft that rides WeChat’s calling feature with zero user interaction on iPhones and Android alike. Calif’s tests ran on iOS 26.6, where the flaw lives in WeChat’s VoIP call handling as a remotely triggerable memory corruption bug.
The caller has to sit on the target’s contact list, a hurdle Calif says matters little once infections start, because every account the worm seizes becomes a fresh launch point against friends who trust it. Accepting the call changes nothing, since victims hear silence and the exploit still runs; declining only postpones the attempt, as the caller can ring again at a quieter moment.
A hijacked account exposes messages, calls, and the payment and mini-program functions tied to it. Account-level control is as far as WeWorm goes on its own, but Calif argues that paired with other bugs it has reported, the chain can grow into complete device takeover.
Within weeks of the July disclosure, Tencent had the hole covered on two fronts. The company confirmed on August 28 that its servers now reject the attack outright, a shield that protects users who never updated, while the app repair itself arrived a week earlier with builds 8.0.76 for iOS and 8.0.77 for Android. No confirmed victims exist and no advisory has appeared. Calif credits AI for finding it and producing its first remote code execution exploit in about two days; full technical details are reserved for a conference talk.