WeChat zero-click call bug allowed silent account takeover

WeChat zero-click call bug allowed silent account takeover

Security firm Calif built a worm that hijacked WeChat accounts through incoming calls, with no answer needed; Tencent has blocked the exploit.

A security firm has demonstrated that an attacker could take over a WeChat account just by placing an incoming call, without the recipient answering or touching the phone. Researchers at Calif built a worm, a program that can spread itself from one device to another, and showed it spreading among three test phones. The person being called does not have to answer or touch the phone for the attack to work, but the caller must already be one of the target's WeChat contacts. Calif reported the flaw to Tencent in July, and Tencent has since blocked the exploit for all users. No real-world attacks using the flaw have been reported, and Calif does not say any took place.

The attack is a zero-click exploit, a type of attack that needs no tap, click or answer from the person being targeted. If the recipient picks up the call, the exploit still works, and they hear nothing on the line, according to Calif. Declining the call ends that particular attempt, but the attacker can simply call again later, for example while the person is asleep. The contact-list requirement is not much of a barrier, Calif said, because WeChat grants extra trust to contacts, and once a contact account is taken over that trust works in the attacker's favour. The demonstration showed one Android phone call an iPhone and take over its WeChat while the phone was still ringing. The compromised iPhone then called a second Android phone and took control of it the same way. Calif's write-up describes routes an attacker could use rather than ones it tested.

Once the exploit runs, the attacker has full control of the WeChat account. They can read and send messages, make calls and act as the account's owner. On its own, the bug does not give control of the phone itself. For many users, WeChat is more than a chat app: its App Store listing covers payments, official accounts and mini programs inside the app. Tencent reported combined monthly active users of WeChat and Weixin at 1.439 billion as of 30 June 2026 in its second-quarter results. That scale makes a silent account takeover particularly serious, because a compromised account can be used to message contacts, move payments or open mini programs in the victim's name.

Tencent released WeChat version 8.0.77 for Android and version 8.0.76 for iOS on 21 August, according to its own release log. Calif said those releases mitigated the bug, and on 28 August it confirmed the exploit was blocked on Tencent's servers as well. The researchers said Tencent has 'mitigated our exploit for all users'. Asked whether the underlying flaw had also been fixed, Calif told The Hacker News it could not comment. Tencent has published no advisory about the flaw, and its release notes for the iOS version and its App Store entry describe the update only as bug fixes. Because the block runs on Tencent's servers, users do not need to install anything to be protected, but running the current version is still the safer choice. On 8 September, the App Store listing showed version 8.0.76 as current.

Calif told The Hacker News it tested the exploit against WeChat 8.0.76 for Android and 8.0.75 for iOS, each one version below the release Tencent shipped on 21 August. The tests ran on iOS 26.6 and some older Android versions. Neither company has published a full list of affected versions, so a user on a different build cannot tell whether it was vulnerable. Tencent also ships WeChat clients for HarmonyOS, Windows, Mac and Linux on their own release schedules. Calif declined in the same reply to say whether it had tested any of them, and Tencent has not addressed them.

Calif is holding back the technical details and plans to present the full analysis at a conference. It has not published anything a defender could search for, and there is no way for a user to tell whether they were called. Checks on 8 September found no CVE identifier, the standard public number used to track known security flaws, and no advisory on Tencent's security response site, which lists its latest announcement as April 2022. The Hacker News has contacted Tencent for comment. Calif said it worked with AI to find the bug and write the first exploit that could run code on the phone in about two days. Building the worm took another week. It designed a set of skills that guide an AI in exploring potential attack surfaces in messaging apps, and the AI discovered this flaw using them. A longer timeline in the post says the engineering team knew of the bug on 23 July, the first Android exploit was finished on 30 July, and the worm demo was completed on 11 August. The post does not say whether the shorter figures count only working time.

Zero-click attacks are not new. Last year, WhatsApp patched a flaw that it said may have been used in targeted attacks. The WeChat case is a reminder that incoming communications should be treated with care even when they appear to come from a known contact, because a contact's account can be turned against you. For organisations that link messaging or payment tools to business systems, AEU-I provides security-first IT, infrastructure and consulting, helping to assess where privileged accounts are used and reduce the blast radius of a compromised login.

How to Protect Yourself

  1. Update the WeChat app on your phone right now through your usual app store, and switch on automatic updates so future fixes arrive without you having to remember.
  2. Regularly look through your WeChat contact list and remove anyone you no longer know or trust, because this attack only works from someone already on that list.
  3. Be careful about calls from contacts who act strangely, and if a call comes at an odd hour from a contact, simply decline it instead of answering.
  4. Watch your WeChat account for messages you did not send or calls you did not make, and if you see anything strange, change your password and sign out other devices.
  5. Keep the rest of your phone's apps up to date too, since attackers often look for the same kind of weakness in different messaging programs.

Terms Explained

  • zero-click attack A type of attack that works without the person being targeted tapping, clicking, opening or answering anything.
  • worm A piece of malicious software that can spread from one device to another on its own.
  • exploit Code that takes advantage of a weakness in software to make the program do something it should not do.
  • contact list The list of people a user has added as trusted friends or contacts inside an app.
  • mitigated Reduced or blocked the harm of a problem, even if the underlying flaw has not been fully repaired.
  • monthly active users The number of distinct people who use a service at least once during a calendar month.

Related AEU services

  • AEU-I IT and security consulting