Security researchers at Calif have developed a worm that can take over WeChat accounts through incoming calls, even when the person receiving the call does not answer or interact with their phone.
The researchers demonstrated the attack spreading between three test phones and said Tencent has since blocked the exploit for all WeChat users.
The attack only works when the caller is already listed as a contact on the target’s WeChat account. Calif said this requirement is not a major obstacle because once an attacker’s contact account is compromised, the trust WeChat gives to contacts can help the attacker spread the attack to other users.
Answering the incoming call does not prevent the attack. Calif said a person who answers hears nothing while the exploit continues to work. Declining the call stops that particular attempt, but an attacker can simply call again later, including when the target may be asleep.
The researchers demonstrated the worm by having an Android phone call an iPhone and take control of its WeChat account while the phone was still ringing. The compromised iPhone then called another Android phone and successfully took over its WeChat account using the same technique.
Once the exploit runs, Calif said an attacker can gain full control of the victim’s WeChat account. This can allow them to read and send messages, make calls and use the account as though they were the legitimate owner. The exploit itself does not provide control over the victim’s entire phone.
The risk is significant because WeChat is used for much more than messaging. The app also includes payments, official accounts and mini programs. Tencent reported that WeChat and Weixin had a combined 1.439 billion monthly active users as of June 30, 2026.
Calif reported the vulnerability to Tencent in July. Tencent subsequently released WeChat version 8.0.77 for Android and 8.0.76 for iOS on August 21. Calif said the releases mitigated the vulnerability and that it confirmed on August 28 that the exploit had also been blocked on Tencent’s servers.
The researchers said Tencent had “mitigated our exploit for all users.” However, Calif said it could not comment on whether the underlying vulnerability itself had been fixed. Tencent has not published a security advisory describing the flaw, and its release notes only mention general bug fixes.
Because the exploit was blocked on Tencent’s servers, users do not need to install anything specifically to stop the attack. Calif still recommends using the latest version of WeChat. The researchers tested the exploit against Android version 8.0.76 and iOS version 8.0.75, which were the versions immediately before Tencent’s August 21 releases.
The researchers tested the attack on iOS 26.6 and some older Android versions, but neither Calif nor Tencent has published a complete list of affected versions. That means users running other builds cannot determine from the available information whether their particular version was vulnerable.
WeChat is also available on HarmonyOS, Windows, Mac and Linux, but Calif did not say whether it tested those versions. Tencent has also not specifically addressed whether those clients were affected.
Calif is keeping the technical details of the vulnerability private for now and plans to present its full analysis at a conference. The company has not published indicators that defenders could use to search for exploitation, and there is currently no way for users to determine whether they were previously targeted by the attack.
As of September 8, no CVE identifier had been assigned to the vulnerability, and Tencent had not published an advisory about it on its security response site. Calif said it used AI to help discover the flaw and develop its first exploit capable of running code on a phone in about two days.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The company said it created a collection of AI-guided skills designed to explore messaging applications and identify potential attack surfaces. According to Calif, the AI used those skills to discover the WeChat vulnerability. Its detailed timeline, however, shows that the engineering team identified the bug on July 23, completed the first Android exploit on July 30 and demonstrated the worm on August 11.



