WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Read original article ↗AI Summary
Researchers at Calif demonstrated a zero-click worm exploiting a vulnerability in WeChat that allows full takeover of a user's account via an incoming call, without requiring any interaction from the target. The exploit spreads laterally by leveraging compromised accounts to call other contacts, enabling rapid propagation across devices. The attack works even if the call is not answered, though declining the call stops that particular attempt. Tencent mitigated the exploit server-side and released client updates (Android 8.0.77, iOS 8.0.76) in August 2026, but has not issued a formal advisory or CVE. No real-world attacks have been observed, and technical details have been withheld pending a future conference presentation.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.