Particle.news
Download on the App Store

WeChat Zero‑Click Worm Can Hijack Accounts Through Incoming Calls

Researchers say the exploit used a memory‑corruption bug in WeChat’s VoIP code and that platform updates plus a server block have stopped the attack.

Overview

  • Calif researchers built a proof‑of‑concept worm called WeWorm that can take over a WeChat account when a user receives a ringing call without any interaction.
  • The team says it found the VoIP memory‑corruption bug in July, built a remote‑code‑execution exploit by late July and demonstrated cross‑platform spread in mid‑August.
  • Tencent released patched mobile builds on August 21 and applied a server‑side mitigation by August 28 that the company says has blocked the exploit for all users.
  • The attack requires the caller to be in the victim’s WeChat contacts but can scale because a compromised contact can be used to reach more victims; once run the exploit gives full control of the WeChat account to the attacker.
  • Calif withheld technical details while planning a conference presentation and warned that use of large language models sped exploit development, raising worry that AI will make similar attacks easier; checks found no public CVE or evidence of in‑the‑wild exploitation.