Sunday, 20 Sep 2026
Get Newsletter
Buy Gear
AppleThreat
Search
  • Home
  • News & Alerts
  • Features
  • Spotlight
  • Reviews
  • About
    • Mission
    • Services
    • Contact
  • Store
AppleThreatAppleThreat
Font ResizerAa
Search
  • Home
  • Blog
  • Contact
Follow US
Malware & Threats

New worm turns an incoming WeChat call into an account takeover

A zero-click worm demonstrated by security firm Calif can seize a WeChat account through a single incoming call on iOS and Android.

AppleThreat Staff
Last updated: September 10, 2026 5:29 am
By
AppleThreat Staff
AppleThreat Staff
ByAppleThreat Staff
Follow:
2 Min Read
Share
SHARE

A voice call alone can now put a messaging account in an attacker’s hands, with no answer, tap, or install required from the victim. A demo moved the takeover from an Android phone to an iPhone and on to a second Android device.

The work comes from the security firm Calif, which named the exploit WeWorm and describes it as the first self-propagating account theft that rides WeChat’s calling feature with zero user interaction on iPhones and Android alike. Calif’s tests ran on iOS 26.6, where the flaw lives in WeChat’s VoIP call handling as a remotely triggerable memory corruption bug.

The caller has to sit on the target’s contact list, a hurdle Calif says matters little once infections start, because every account the worm seizes becomes a fresh launch point against friends who trust it. Accepting the call changes nothing, since victims hear silence and the exploit still runs; declining only postpones the attempt, as the caller can ring again at a quieter moment.

A hijacked account exposes messages, calls, and the payment and mini-program functions tied to it. Account-level control is as far as WeWorm goes on its own, but Calif argues that paired with other bugs it has reported, the chain can grow into complete device takeover.

Within weeks of the July disclosure, Tencent had the hole covered on two fronts. The company confirmed on August 28 that its servers now reject the attack outright, a shield that protects users who never updated, while the app repair itself arrived a week earlier with builds 8.0.76 for iOS and 8.0.77 for Android. No confirmed victims exist and no advisory has appeared. Calif credits AI for finding it and producing its first remote code execution exploit in about two days; full technical details are reserved for a conference talk.

TAGGED:account takeoveriOS securityTencentWeChatWeWormwormzero-click
SOURCES:The Hacker NewsThe RegisterSecurity Affairs
Share This Article
Email Copy Link Print
Previous Article Turkey retires ministers’ iPhones after Apple spyware alerts
Next Article A dark smartwatch emitting neon white sound waves in a navy void Conversation recaps on Apple’s new watch stir consent worries
AppleThreat

About Magazine: covers the latest in art and cultural discourse. From emerging artists to critical conversations, we explore where creativity meets thought. Insightful, bold, and always curious.

Quick Links
  • Blog
  • Contact
  • Illuminated Home
  • Sample Page

© 2026 AppleThreat.com. All Rights Reserved.
Privacy Policy | Legal