WeWorm – First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A proof-of-concept zero-click worm dubbed “WeWorm” that it says can spread through WeChat voice calls on both iOS and Android, compromising a target’s WeChat account in seconds without the victim answering the call.

Calif says the bug was reported to Tencent in July and that Tencent has since mitigated the exploit for users, but the research still serves as a stark warning about how mobile messaging apps can become wormable attack surfaces at planetary scale.

WeChat is not a niche target. Tencent says Weixin and WeChat together exceeded 1.4 billion monthly active users as of the end of Q1 2026, while WeChat’s own site describes the platform as serving over 1 billion users with chats and calls across major mobile and desktop platforms.

That sheer reach is what makes Calif’s demonstration so alarming: a memory-corruption flaw in the app’s VoIP stack is not just another messaging bug, but a potential entry point into one of the world’s most deeply embedded communications ecosystems.

According to Calif’s public research listing, WeWorm is described as “the first zero-click worm to spread through WeChat calls across iOS and Android,” and it was published on September 8, 2026, as part of the company’s Android-tagged research work.

Calif frames the finding not as a theoretical edge case but as a live demonstration of how a trusted messaging relationship can be weaponized, with one compromised contact becoming the launch point for attacks against everyone in that person’s social graph.

The company’s demo chain reportedly used three phones to prove cross-platform propagation. A Pixel 10a was used as the initial attacker device, which then called an iPhone 17e and exploited the flaw while the call was still ringing; the compromised iPhone was then used to call another Pixel 10a, which was reportedly taken over in the same way.

In practical terms, that is the textbook definition of a wormable condition in a communications app: the attacker calls the victim, the victim becomes the attacker, and the infection path continues with almost no friction.

What makes the scenario especially dangerous is the “zero-click” aspect. Calif says the victim does not need to answer the call or interact with the phone at all for exploitation to succeed, and even if the person does answer, they hear nothing while the compromise still goes through.

That claim places WeWorm in the most feared class of mobile exploits, where normal user caution offers little protection because there is no malicious link to avoid and no attachment to reject.

Calif also says exploitation yields full control of the victim’s WeChat account, including the ability to read and send messages, place calls, and act on the user’s behalf inside the app.

On its own, account takeover at that level would already be severe for identity abuse, surveillance, fraud, and lateral targeting; chained with additional device-level bugs, Calif says the same access could be extended to full control of the underlying Android or iOS device.

The company specifically links that possibility to its broader AI-assisted exploit research, including Android work such as OEMpocalypse, which it has presented as a path from app-level access to root on several vendor ecosystems.

One condition slightly narrows the attack surface: the attacker must already be on the victim’s friend list. But Calif argues that this is a weak barrier in real-world conditions because once a single trusted contact is compromised, that person’s account can be used to reach additional friends, turning the victim’s social trust network into the worm’s propagation layer.

That is a familiar and troubling pattern in modern communications security, where safety features and trust assumptions designed for convenience can become force multipliers once an adversary gets an initial foothold.

The technical root cause, Calif says, is a memory-corruption bug in WeChat’s VoIP stack, though the company is withholding full exploit details until a later conference presentation.

That restraint matters because memory-corruption flaws in real-time communications code are among the most sensitive bug classes in mobile security, especially when they sit inside call-handling paths that process network data before a user takes any action.

Calif further suggests that this bug is only one example of a broader class of “unconventional attack surfaces” spread across messaging apps, hinting that similar issues may exist in other platforms with rich calling and media features.

WeWorm may be a demo, but its significance is real. Calif has effectively shown that mobile messaging worms are no longer a distant nightmare or a plot device for conference talks; they are a practical research outcome in 2026, built against one of the world’s largest communications platforms and developed at AI speed.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post WeWorm – First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android appeared first on Cyber Security News.