-
A cybersecurity firm named Calif built a worm that hijacks WeChat accounts through an incoming call, and the target never needs to pick up.
-
The worm jumped across three test phones during a live demo, moving from an Android device to an iPhone, then back to another Android phone.
-
Tencent has blocked the exploit on its own servers, but the company has not released a public advisory or confirmed a complete fix.

A phone call from a friend usually feels harmless. New research from security firm Calif shows that a single WeChat call can hand your account to a stranger.
The researchers built a worm that spreads through calls alone. It needs no click, no download, and no answered call to work.
How One Call Can Hijack a WeChat Account
Calif’s researchers built a worm that takes over a WeChat account through an incoming call. The person receiving the call does not need to answer it. They do not even need to touch their phone. The attack still runs in the background.
There is one condition. The caller must already be on the target’s WeChat contact list. Calif said this barrier does not block much. Once a contact gets taken over, WeChat gives that contact extra trust. That trust then works for the attacker, not the victim.
Answering the call will not stop the attack either. A person who picks up hears nothing at all, and the exploit still runs. Declining the call does end that single attempt. But the attacker can simply call again later, perhaps while the target sleeps.
The live demo showed how the worm spreads. The iPhone’s WeChat account was hijacked while the phone was still ringing. That compromised iPhone then called a second Android phone and took it over the same way.
Once the exploit runs, researchers said the attacker gains full control of the WeChat account. They can read messages, send new ones, place calls, and act exactly like the real owner. The attack does not hand over control of the phone itself.
It stays limited to the WeChat account. No attacks using this method have been reported so far, and Calif has not claimed otherwise. Zero-click attacks that need no action from a victim are not new. Last year, WhatsApp patched a similar flaw it said may have hit real targets.
Tencent Moves to Block the Exploit, but Questions Remain
WeChat is not just a chat app for most users. According to Tencent’s own App Store listing, the platform also handles payments, official accounts, and small in-app programs called mini programs. Tencent reported combined monthly active users of WeChat and its sister app Weixin at 1.439 billion as of June 30, 2026.
Tencent shipped version 8.0.77 for Android and 8.0.76 for iOS on August 21, based on its own release records. Calif said these updates fixed the bug. On August 28, the firm confirmed the exploit no longer worked because Tencent had blocked it on its servers too.
The WeChat flaw is not Tencent’s only security concern. In May 2026, a dark web claim alleged that a threat actor obtained 1.4 billion records linked to Tencent, including QQ email addresses, phone numbers, and account IDs, in a 44GB archive.
According to Calif, Tencent has now “closed off our attack method for every user.” The firm was asked whether the root flaw behind the exploit had also been patched. Calif told The Hacker News it could not answer that question. Tencent has not published any advisory about the bug. Its release notes for the update only mention general bug fixes.
Because the block sits on Tencent’s servers, users do not need to install anything new to stay safe. Still, running the newest version remains the safer choice. As of September 8, the App Store listing for WeChat showed version 8.0.76, released August 21, as current.
Calif said it tested the exploit against WeChat 8.0.76 for Android and 8.0.75 for iOS. Both were the versions released just before Tencent’s August 21 update. Tests ran on iOS 26.6 and older Android builds. Neither company has shared a full list of which versions were vulnerable, so users on other builds cannot check for themselves.
Tencent also builds separate WeChat versions for HarmonyOS, Windows, Mac, and Linux, each on its own release schedule. Calif declined to say whether it tested any of these versions. Tencent has not addressed them either.
Checks on September 8 found no official CVE number for the flaw. Tencent’s security response site listed no new announcement, with its most recent post dated back to April 2022. The Hacker News has reached out to Tencent for comment.
How Researchers Found the Bug Using AI
Calif said it used artificial intelligence to search for the flaw. The firm’s AI wrote the first working exploit capable of running code on a phone in roughly two days. Building the full worm took about one more week, Calif said.
Calif explained that it had built a set of instructions, or skills, that guide an AI system as it hunts for weak spots in messaging apps. The AI reportedly found this specific WeChat flaw using those very skills.
Calif’s own internal timeline tells a slightly longer story. Its engineering team first learned about the bug on July 23. The first working Android exploit was ready by July 30. The full worm demo followed on August 11. Calif’s post does not clarify whether the shorter two-day and one-week figures count only active working hours.
Calif is holding back most technical details for now. The firm plans to present its complete findings at a security conference later on. Nothing that a copycat attacker could easily search for or reuse has been published yet. Because of this, there is currently no way for an ordinary WeChat user to know whether they were ever targeted by a call like this.
For now, keeping WeChat updated remains the simplest precaution available to users. Anyone waiting on more details should watch for an official statement, since Tencent has not published one yet.