Skip to main content
LiMP VPN
All news

WeChat WeWorm: Account Hijacked Before You Answer the Call

WeChat WeWorm: Account Hijacked Before You Answer the Call

In short: Security firm Calif disclosed WeWorm — a self-spreading worm in WeChat's VoIP stack that hijacks accounts during an incoming call, before the victim answers. Tencent deployed a server-side block on 28 August 2026; app patches shipped on 21 August. No real-world exploitation has been confirmed.

What happened

On 7–8 September 2026, security firm Calif published technical details about a zero-click vulnerability in WeChat. The exploit abuses a memory corruption bug in WeChat's VoIP stack — the component that handles incoming calls. When the target's device begins ringing, the vulnerable code triggers during the call setup phase, with no action required from the user.

We covered a similar class of attack in our article on AirDrop and Quick Share zero-click vulnerabilities. WeWorm belongs to the same threat category: no interaction is needed, and the attack vector is a normal communication channel.

How WeWorm works

The only prerequisite: the attacker must be in the victim's WeChat contact list. From there, a single call is enough. When the device receives the call, WeWorm sends a specially crafted packet through the vulnerable VoIP stack, triggering remote code execution with WeChat's privileges.

The result: the attacker gains full account control — reading and sending messages, making calls as the victim, and accessing chat history. More critically, WeWorm is self-spreading: after taking over an account, it automatically sends calls or messages to all of the victim's contacts, turning a single compromise into a chain reaction. Calif built a working prototype in roughly two days using AI tools for binary analysis. For a broader look at mobile privacy threats, visit our privacy and security blog.

Who is at risk

WeChat has over 1 billion users — primarily in China, and among those doing business with Chinese partners or staying in contact with the diaspora. Account takeover exposed all WeChat conversations: business discussions, personal messages, and media files.

The self-spreading mechanism made this especially dangerous in corporate environments: a single compromised account could trigger a chain of takeovers across an entire organization if employees are in each other's contact lists. The critical detail: the app could be attacked while running in the background — phone on a desk, screen off. This is what distinguishes zero-click attacks from phishing, where victims must be tricked into clicking something.

Is the vulnerability fixed

Yes. Calif followed responsible disclosure, and Tencent responded promptly. App patches shipped on 21 August 2026: WeChat for Android 8.0.77 and WeChat for iOS 8.0.76. On 28 August, Tencent added a server-side block as a safety net for users who had not yet updated. Tencent reported no confirmed real-world attacks; researchers noted this refers only to publicly documented cases.

How to protect yourself

Update WeChat immediately. If you are running a version below Android 8.0.77 or iOS 8.0.76, update through the App Store or Google Play. The server-side block reduces risk, but the app patch closes the vulnerability definitively.

Enable WeChat's two-step verification. An extra authentication layer makes unauthorized access harder, even if account credentials are exposed through another channel.

Review your contact list. WeWorm requires the attacker to be in the victim's contacts. Remove anyone you do not know or trust.

Secure the network layer. LiMP VPN encrypts all device traffic, protecting you from interception on public and corporate networks. A VPN does not patch application-level vulnerabilities — only the update does that — but it secures the network layer. See our pricing plans to find the right fit.

Sources

WeChat WeWorm: Account Hijacked Before You Answer the Call