Tencent patched a zero-click WeChat call flaw that let a worm spread and take over accounts on iPhone and Android

Tencent fixed a serious WeChat security flaw that let a trusted contact take over another user’s account just by placing a call, without the victim answering. Researchers at Calif said a memory-corruption bug in WeChat’s VoIP calling stack enabled cross-platform remote code execution and worm-like spread from one friend account to another on iOS and Android. No CVE was cited in the article; Tencent reportedly pushed fixes on August 21 and researchers are withholding full exploit details.
Why it matters: WeChat has more than 1.4 billion monthly users, so a zero-click call bug with worm behavior is unusually dangerous even if some exploit details are still private. Users should update WeChat immediately, and defenders should treat unusual call-driven account activity as potentially malicious.

Sources

WeChat worm could pwn a friend before they even answered the call
2026.09.09 100% relevant
This article appears to be the first tracked item establishing the patched WeChat zero-click wormable call exploit as a distinct event.
← Back to all stories