Vulnerability
Published 2026-09-08
Verified 2026-09-19

WeChat zero-click worm via incoming contact call (Calif lab demo; Tencent patched)

The Hacker News (8 September 2026) reports security firm Calif built a worm that takes over a WeChat account via an incoming call and demonstrated spread across three test phones. The callee does not need to answer or touch the phone, but the caller must already be a WeChat contact. Calif reported the flaw to Tencent in July and says the company has since shipped a fix (wire does not name a CVE in the RSS abstract). Treat as a messenger client/patch urgency item for WeChat on iPhone and Android; confirm your app store build is current. Wire-only until a Tencent/CVE primary is linked. Primary wire: The Hacker News.

Product
Tencent WeChat (iOS / Android clients in Calif demo)
Versions
Vulnerable builds prior to Tencent’s post-July 2026 fix (exact build numbers not in wire abstract)
Exploited in Australia?
unknown
Patch to
Update WeChat from official stores; restrict contact requests; watch for unexpected account activity after missed calls from contacts

Primary: The Hacker News — WeChat Calif worm (8 Sep 2026)

vulnerabilities identity australia