Zero-click worm exploits WeChat VoIP bug to hijack accounts without answering calls
Researchers at Calif uncovered a zero-click vulnerability in WeChat’s VoIP stack that lets a trusted contact seize control of a user’s account within seconds, even if the call is never answered.
Calif’s security team identified a memory-corruption bug in WeChat’s VoIP stack that enables a zero-click worm, named WeWorm, to take over a victim’s account in seconds without the call being answered. The attack works on both iOS and Android, leveraging the victim’s trusted-contact list to bypass authentication. After Tencent issued a fix on August 21, Calif released a demonstration showing the compromised account automatically dialing another contact and repeating the infection cycle, which stops only if the call is declined.
The researchers warn that, when combined with other reported Android and iOS vulnerabilities, the worm could lead to full device compromise. They used AI to discover and develop the exploit in roughly two days and plan to present a detailed analysis at an upcoming conference. Experts, including Georgetown University’s Ryan Fedasiuk, stress the broader implications for cyber-security as AI lowers the barrier for creating such attacks.
Why it matters
A zero-click worm in a platform with 1.4 billion users shows how AI-driven exploits can threaten billions of devices worldwide.
In this story
