WeChat worm could pwn a friend before they even answered the call
Security researchers at Calif have uncovered and helped patch a zero-click vulnerability in WeChat that allowed a malicious call from a trusted contact to hijack a user's account without them even answering the phone. The flaw, dubbed WeWorm, stemmed from a memory corruption bug in WeChat's VoIP stack and is described as the first zero-click worm able to spread through WeChat calls on both iOS and Android, raising serious concerns given the app's enormous user base and the ease with which it could propagate through contact lists.
In demonstrations, the exploit seized control of a victim's account within seconds of a call being placed, then automatically used the compromised account to call and infect further contacts, all without any user interaction; only declining the call stopped the attack. Tencent, WeChat's owner, pushed fixes on 21 August, though Calif is withholding full technical details until a planned conference presentation. Calif said it used AI to discover the bug and build a working remote-code-execution exploit in roughly two days, and warned the flaw could be chained with other device-level bugs for full device takeover. Georgetown academic Ryan Fedasiuk called the find "an extremely serious incident" and urged closer US-China cooperation on cyber threats as AI lowers the barrier to such attacks.
- WeChat had a zero-click worm bug letting calls hijack accounts instantly
- Tencent patched it 21 August; full exploit details still withheld
- Researchers used AI to find the bug and build an exploit in two days