Connect with us

NEWS

WeChat’s Missed-Call Worm Seized Accounts Before Anyone Answered

Calif’s WeWorm showed a WeChat call can take over an account mid-ring, a VoIP flaw Tencent blocked while other messengers stay untested.

Published

on

Calif, a Palo Alto security firm, showed a WeChat worm that seized accounts while the phone was still ringing, then dialed the victim’s friends. Tencent blocked the trick on its servers and in WeChat 8.0.77 for Android and 8.0.76 for iOS, and has said it has no reason to believe customers were hit.

The same kind of incoming-call bug has been used to break phones since WhatsApp’s 2019 missed-call exploit, and Calif says WeChat is one case in a larger set of messaging call surfaces it is still probing.

The Worm Jumped Across Three Test Phones

Calif published the demo on September 8 under the name WeWorm, calling it the first zero-click worm to spread through WeChat calls across iOS and Android. The write-up is the first note in a series on zero-click bugs in mobile messaging apps. The team used three handsets and let the call graph do the rest.

THE THREE-PHONE HOP

  • Phone one: A Pixel 10a, used as the attacker, placed a WeChat call to an iPhone 17e.
  • Phone two: The iPhone’s WeChat account was taken while the handset was still ringing, then that account called the next device.
  • Phone three: A second Pixel 10a was taken the same way, so the victim became the next attacker.

Calif posted a separate Android remote-code demo of the same bug, which is the clip to watch if you want to see the ring land and the session change hands.

The caller had to be on the target’s WeChat friend list. That sounds like a brake until you remember the worm’s job is to steal that list and keep dialing. An attacker who owns one account can reach everyone that account already trusts.

What WeWorm Could Take From an Account

Once the ring landed, Calif had the WeChat account in seconds. The firm could read and send messages, place calls, and act on the victim’s behalf. Chained with other Android and iOS bugs it has reported and is helping fix, that access can become control of the whole device.

The person being called does not have to pick up or touch the phone. If they do answer, they hear silence, and the exploit still works. Declining the call stops that attempt, though the caller can try again later, including while the owner is asleep.

Friend Lists Turn One Hack Into Many

WeChat is the daily app for people in China and for Chinese communities abroad, a so-called everything app for chat, payments, rides, and official services. Tencent’s second-quarter results list 1,439 million combined monthly users for Weixin and WeChat as at June 30, 2026, up 2% from 1,411 million a year earlier. Calif’s own ceiling is blunter: if the worm ran free, actors could compromise over a billion phones or accounts.

Treating this as a China-intranet curiosity misses how the hop actually works. The blast radius is the friend graph, and that graph already crosses borders. A compromised contact in Shanghai can ring a relative in Vancouver, and the second phone does not have to belong to the original target.

WeChat, like many messaging apps, gives trusted contacts more privileges. But once one contact is compromised, that trust works against you.

Calif, WeWorm research note, September 8, 2026

The firm says a skilled attacker has other ways onto that first account, including bugs in other apps and Android tricks it has already documented under the name OEMpocalypse. The WeChat call is the spreader, not the only door.

Tencent Logged the Patch as Bug Fixes

Calif sent the bug to Tencent on July 24. Client builds that stopped the demo went out on August 21: WeChat 8.0.77 on Android and 8.0.76 on iOS. On August 28, Calif confirmed Tencent had also blocked the exploit on its servers for all users, so protection did not wait on everyone installing a store update.

HOW TENCENT CLOSED THE DEMO

Layer Date What landed
Android client August 21, 2026 WeChat 8.0.77
iOS client August 21, 2026 WeChat 8.0.76
Server-side block August 28, 2026 Exploit blocked for all users

The public notes did not name a VoIP flaw. WeChat’s iOS listing for 8.0.76 describes the release as Bug fixes and improvements, the same line the app has used on version after version. Tencent published no CVE and no list of which builds were exposed, so a user cannot check whether the copy they ran in July or early August was one of them. Running a current build is still the safer move, even with the server-side kill in place.

Tencent later confirmed to Calif, on September 4, that the bug could be used for remote command execution. That confirmation came after both the store builds and the server block. Calif has said the exploit is now mitigated for all users and has thanked Tencent for the work.

WhatsApp Already Lived This Missed Call

A ringing messenger call that runs code before anyone picks up is not a new idea. In May 2019, WhatsApp patched CVE-2019-3568, a buffer overflow in WhatsApp’s VoIP stack that let attackers run code by sending crafted RTCP packets to a phone number. Targets did not have to answer. NSO Group used that path to install Pegasus on about 1,400 phones. WhatsApp shipped Android 2.19.134 and iOS 2.19.51 to close it, and it also pushed server-side changes.

WEWORM VERSUS CVE-2019-3568

Point WeWorm, WeChat, 2026 CVE-2019-3568, WhatsApp, 2019
Trigger Incoming WeChat VoIP call Incoming WhatsApp VoIP call
User action None; the ring is enough None; a missed call is enough
Bug class Memory corruption in the VoIP stack Buffer overflow in the VoIP stack, CVSS 9.8
Who can call A WeChat friend A phone number
Shown result Full WeChat account control, then more calls Device code execution and Pegasus on about 1,400 users
Client fix Android 8.0.77, iOS 8.0.76 Android 2.19.134, iOS 2.19.51

The differences matter. WeWorm as shown takes the WeChat account, not the whole phone, and it cannot spray strangers because the caller has to be a saved friend. WhatsApp’s 2019 bug was a device-level hit from a number you might never have seen. What they share is the place the parser sits: call-setup data that the app handles before a human has decided to pick up.

Banned Accounts, Then a Working Exploit

Calif says its AI found the WeChat bug sometime in July, and that working with those models the team found the flaw and wrote the first remote code execution exploit in about two days. Building the worm took one more week. A project on this scale, the firm wrote, used to take a larger team months. The dated log is more stop-start than that slogan, and it includes a four-day ban on Calif’s own WeChat accounts after the report went in.

THE DISCLOSURE CALENDAR

  1. July 23, 2026: Calif engineers become aware of the bug the AI had found.
  2. July 24, 2026: The firm submits the bug to Tencent.
  3. July 25 to July 28, 2026: Calif’s WeChat accounts are banned, then restored on July 29.
  4. July 30, 2026: The first Android remote code execution exploit is finished.
  5. August 2, 2026: The iOS exploit is finished.
  6. August 11, 2026: The polished worm demo runs across Android and iOS.
  7. August 21, 2026: Tencent publishes Android 8.0.77 and iOS 8.0.76.
  8. August 26, 2026: Tencent tells Calif it is assessing the issue.
  9. August 28, 2026: Calif confirms a server-side block for all users.
  10. September 3, 2026: Calif shares its technical analysis and working exploits with Tencent.
  11. September 4, 2026: Tencent confirms the bug can be used for remote command execution.
  12. September 8, 2026: Calif publishes WeWorm.

The client patches landed 28 days after the July 24 report. Calif is withholding the technical guts and plans to present the full analysis at an upcoming conference. Thai Duong, Calif’s chief executive, framed the release as a case for the United States and China to work with private labs on using AI to find this class of bug faster than it can be turned into a worm.

Calif Is Already Probing Other Chat Apps

The bug itself is memory corruption in WeChat’s VoIP stack. That is all Calif will say for now. The larger claim in the note is that this WeChat case is not a one-off parser accident in one Chinese super-app.

This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps. We’re conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction.

Calif, WeWorm research note, September 8, 2026

Some of that reduction, the firm says, depends on platform owners, not only on Tencent. Until that work is further along, the technical details of WeWorm stay unpublished. The warning underneath is about speed. Calif argues these tricks have long lived with well-funded shops, and that AI now lets smaller teams find and weaponize them, which is why it published the demo at all.

The lab-accident path is the one the firm does not want to relearn. A half-finished copy that leaks can move before vendors are ready, Calif wrote, which is how WannaCry escaped early tooling and hit hospitals. The easy political reply is to freeze the models. Calif’s line is the opposite: the holes are already in the call stacks, and the same tools that shrink exploit time can shrink patch time if vendors and governments actually use them together.

No CVE and No List of Vulnerable Builds

As of September 8, there was still no CVE identifier for the WeChat flaw, and neither Calif nor Tencent had published which app versions were vulnerable. A person who took a WeChat call in July has no public artifact that says whether that ring was dangerous. Checks of Tencent’s public security-response pages around the disclosure also found no advisory that named the bug.

WHAT WE KNOW

  • The demo: A friend-list WeChat call could take the account on iOS and Android while the phone rang, then dial the next friend.
  • The fix: WeChat 8.0.77, 8.0.76, and a later server-side block stopped Calif’s exploit for all users.
  • The wild: Calif and Tencent have both indicated they have no evidence this was used against real users.

WHAT IS UNCONFIRMED

  • Affected builds: No public list of which WeChat versions could be hit in July and August.
  • Other clients: Calif’s write-up names iOS and Android; it does not say whether HarmonyOS, Windows, Mac, or Linux WeChat clients were tested.
  • Other apps: Calif says it is already looking, but it has not named the next target or the conference where WeWorm’s internals will be shown.

The WeChat copy on phones now is supposed to be closed, and the server filter is supposed to catch the rest. What is still open is the thing Calif actually set out to flag: call-setup code in messengers that still trusts a ring from a friend, and patch notes that still describe that kind of bug as a routine cleanup.

Harry is the editor of WORLDHAB, an independent publication that he owns and edits himself. His decade in journalism started in reporting and moved into editing, and it left him with a short list of promises that readers can expect every article here to keep. Sources are named and linked, so a claim about a company, a government or a team can be traced to the statement, filing or transcript it came from. Dates are given in full, figures are checked against the original table before publication, and where a number is an estimate the story says whose estimate it is. Headlines describe what happened rather than tease it. Those expectations hold across all ten sections WORLDHAB publishes for an international audience: news, business, technology and science on one side, sports, entertainment, lifestyle and travel on another, with auto and gaming covered with the same seriousness. Harry keeps a public corrections policy and marks every change on the article it affects. Reader mail is read by him and answered from support@worldhab.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending