How a Zero-Click WeChat Worm Exploits Incoming Calls to Hijack Accounts

A zero-click vulnerability in WeChat allows attackers to take over accounts via ringing calls without user interaction, exposing messages and contacts. Tencent has patched the flaw.

How a Zero-Click WeChat Worm Exploits Incoming Calls to Hijack Accounts
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is the zero-click WeChat vulnerability and why it matters

A critical security flaw was discovered in the VoIP calling features of WeChat, a hugely popular messaging app with over a billion users. This vulnerability allows attackers to hijack a user’s WeChat account simply by placing a call through the app. The user does not need to answer or interact with the call; just receiving the incoming ring is sufficient for compromise. This silent exploitation can expose a victim’s private messages, contacts, and other app data.

This matters because WeChat functions as an all-in-one platform for communication, social networking, and payments. An attacker gaining remote control over an account threatens not only personal privacy but could also disrupt digital payments, identity, and business activities tied to the app.

How does the WeWorm exploit work and spread?

Zero-Click Worm Discovered in WeChat - GovInfoSecurity
Zero-Click Worm Discovered in WeChat - GovInfoSecurity

The exploit, dubbed "WeWorm", leverages a memory corruption flaw found in WeChat's VoIP stack. Attackers can call any WeChat contact from an infected device using either Android or iOS. Once the victim’s phone rings, the attacker’s malicious code executes immediately without user interaction.

If the victim declines the call, the attack halt momentarily, but repeated calls can resume the infection anytime, even when the phone owner is unaware. If the call is answered, no sound is heard by the victim, yet the takeover continues undetected.

Within seconds, the attacker gains full access to the targeted account, including messages and contact lists, enabling further spreading through the victim’s contacts and potentially creating a worm effect across millions of devices.

What Tencent has done and what users should know

Tencent, WeChat’s parent company, was informed responsibly of the vulnerability and promptly released fixes in versions 8.0.77 (Android) and 8.0.76 (iOS). These updates include server-side mitigation, meaning most users will be protected without needing immediate manual updates. However, installing the latest app version is recommended to ensure full protection and benefit from other security improvements.

Currently, there is no evidence that this attack has been exploited in the wild, and WeChat’s payment features include extra authentication measures to help prevent financial fraud related to this flaw.

One limitation is that the patch coverage does not explicitly extend to WeChat versions on platforms like HarmonyOS, Windows, macOS, or Linux, so users on those platforms should exercise caution until further updates or patches are confirmed.

What users should do to protect themselves effectively

China's WeChat makes fix after US firm shows AI hack risk
China's WeChat makes fix after US firm shows AI hack risk
  1. Update WeChat to the latest version available for your device as soon as possible.
  2. Be cautious of unexpected incoming calls within WeChat, especially repeated calls from known contacts if unusual.
  3. Monitor account activity and enable available security features such as two-factor authentication for additional protection.
  4. Consider contacting contacts to inform them about the vulnerability, so they can take precautions.
  5. Stay alert for further security updates from WeChat and Tencent for all platforms you use.

Key takeaway: A wake-up call on zero-click vulnerabilities in everyday apps

This WeChat worm highlights a growing security challenge posed by zero-click vulnerabilities—attacks requiring no user interaction that can stealthily take over devices. Given the increasing integration of messaging apps into daily life, security flaws like this pose significant risks to privacy and trust.

Users must recognize that security depends not only on their behaviors but also on app developers promptly addressing such flaws. Proactive patching and security awareness will remain crucial defenses. While this specific WeChat issue is patched and not yet exploited broadly, it serves as a reminder to keep apps updated and maintain vigilance against emerging threats.

React to this story

Related Posts