WeChat Zero-Click Worm Discovered by Calif, Tencent Patches Exploit
Security researchers at **Calif** have developed and demonstrated a zero-click worm capable of compromising **WeChat** accounts through an incoming call, even if unanswered. While the exploit granted full control over the compromised account, **Tencent** has since implemented server-side mitigations to block the attack.
Researchers at the security firm **Calif** have successfully built a worm that leverages a zero-click vulnerability in **WeChat**. This sophisticated attack allowed for the takeover of a **WeChat** account via an incoming call, without requiring any interaction from the recipient.
**Calif** publicly demonstrated the worm's propagation across three test phones, showcasing its ability to spread autonomously once an initial compromise was achieved.
### The Zero-Click Mechanism
The exploit's core mechanism revolves around an incoming call from an existing **WeChat** contact. Crucially, the target does not need to answer or even touch their phone for the attack to succeed. Answering the call also did not prevent the exploit; victims would hear nothing while their account was being compromised. Declining the call would stop that specific attempt, but an attacker could simply call again later.
While the attacker must be a pre-existing contact, **Calif** noted that this barrier is easily circumvented once an account is taken over, as the compromised account can then propagate the worm to its own contact list, leveraging the inherent trust within the platform.
### Demonstration and Impact
The proof-of-concept demonstration involved an **Android** phone initiating a call to an **iPhone**, successfully taking over its **WeChat** account while the **iPhone** was still ringing. The compromised **iPhone** then proceeded to call a second **Android** phone, compromising it in the same manner.
Once exploited, the researchers stated that an attacker would gain full control over the **WeChat** account, including the ability to read and send messages, make calls, and generally act as the account's legitimate owner. It's important to note that the exploit, on its own, does not grant control over the underlying mobile device.
For many users, **WeChat** is more than just a messaging app, integrating payments, official accounts, and mini-programs. **Tencent** reported a combined monthly active user base of 1.439 billion for **WeChat** and **Weixin** as of June 30, 2026.
### Tencent's Response and Mitigation
**Calif** reported the flaw to **Tencent** in July. **Tencent** subsequently released **WeChat** version 8.0.77 for **Android** and 8.0.76 for **iOS** on August 21. **Calif** confirmed on August 28 that **Tencent** had successfully blocked the exploit on its servers, mitigating the threat for all users.

While **Tencent**'s server-side block means users are protected even without updating, running the latest version remains a best practice. **Tencent** has not published a security advisory or assigned a **CVE** identifier for the flaw, and its release notes only mention general bug fixes.
**Calif** tested the exploit against **WeChat** 8.0.76 for **Android** and 8.0.75 for **iOS**, one version below the August 21 releases. The tests were conducted on **iOS 26.6** and older **Android** versions. The full scope of affected versions across **WeChat** clients for **HarmonyOS**, **Windows**, **Mac**, and **Linux** remains unconfirmed, as **Calif** declined to comment on tests for these platforms.
### AI-Assisted Discovery
Intriguingly, **Calif** reported that an AI played a significant role in the discovery of this bug. The firm stated that it designed a set of skills to guide an AI in exploring and identifying potential attack surfaces within messaging applications, leading to the discovery of this specific flaw.
According to **Calif**, the AI found the bug and wrote the initial code execution exploit in approximately two days, with another week dedicated to building the full worm. While **Calif**'s internal timeline shows longer gaps between stages, the firm highlights the efficiency of AI in vulnerability research.
**Calif** plans to present a full technical analysis of the vulnerability at an upcoming conference, withholding specific details until then. Currently, there is no public information that would allow users to determine if they were targeted by this exploit.