Calif disclosed WeWorm, a proof-of-concept zero-click worm that exploited a memory-corruption vulnerability in WeChat’s VoIP call-handling stack. A malicious voice call could reportedly compromise a WeChat account within seconds while the phone rang, without the recipient answering or interacting. The researchers demonstrated propagation from a Pixel 10a to an iPhone 17e and then another Pixel device, using compromised accounts to call saved contacts across Android and iOS.
Successful exploitation reportedly gave attackers control of the victim’s WeChat account, including access to messages and the ability to send messages, place calls, and impersonate the user; it did not by itself provide full device takeover. Calif reported the flaw to Tencent on July 24, and Tencent mitigated it for users on August 21 before public disclosure. Calif estimates that, absent remediation, WeChat’s scale could have made more than one billion accounts or devices exposed to wormable account compromise, while withholding technical details pending a future conference presentation.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Calif published research describing WeWorm as a proof-of-concept zero-click worm that could propagate through trusted WeChat contacts across Android and iOS. It withheld full exploit details pending a later conference presentation.
Tencent reportedly confirmed in writing to Calif that the WeChat VoIP vulnerability underlying WeWorm was exploitable for remote code execution. This confirmation followed Tencent's release of mitigations for the issue.
Calif confirmed that Tencent had blocked the demonstrated WeWorm attack on its servers. The server-side mitigation could stop the specific exploit even for users who had not installed the August 21 WeChat updates.
Tencent restored Calif's WeChat accounts and released patches that mitigated the reported WeWorm exploit for users.
Calif completed a demonstration of the WeWorm zero-click worm spreading from an Android device to an iPhone and then to another Android device through incoming WeChat calls. The demonstration showed takeover of WeChat accounts rather than control of the underlying phones.
Calif reported the WeChat VoIP vulnerability and exploit to Tencent. Calif said Tencent initially suspended its WeChat accounts following the disclosure.
Calif said it discovered a memory-corruption vulnerability in WeChat's VoIP call-handling stack and developed an AI-assisted exploit chain later named WeWorm. The flaw reportedly enabled zero-click compromise of a WeChat account during a ringing voice call.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
17 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcexakep.ru
Open sourcecysecurity.news
Open sourceinfosecurity-magazine.com
Open sourcethehackernews.com
Open sourceblog.calif.io
Open sourcecalif.io
Open sourcecalif.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.