Vulnerability
Published 2026-09-08
Verified 2026-09-19
WeChat zero-click worm via incoming contact call (Calif lab demo; Tencent patched)
The Hacker News (8 September 2026) reports security firm Calif built a worm that takes over a WeChat account via an incoming call and demonstrated spread across three test phones. The callee does not need to answer or touch the phone, but the caller must already be a WeChat contact. Calif reported the flaw to Tencent in July and says the company has since shipped a fix (wire does not name a CVE in the RSS abstract). Treat as a messenger client/patch urgency item for WeChat on iPhone and Android; confirm your app store build is current. Wire-only until a Tencent/CVE primary is linked. Primary wire: The Hacker News.
- Product
- Tencent WeChat (iOS / Android clients in Calif demo)
- Versions
- Vulnerable builds prior to Tencent’s post-July 2026 fix (exact build numbers not in wire abstract)
- Exploited in Australia?
- unknown
- Patch to
- Update WeChat from official stores; restrict contact requests; watch for unexpected account activity after missed calls from contacts
