CYBERSECURITY

Researchers Uncover Zero-Click WeChat Flaw That Spreads via Incoming Calls

Researchers Uncover Zero-Click WeChat Flaw That Spreads via Incoming Calls

How the Worm Propagates Through Contact Networks

Security experts from California have identified a critical vulnerability in WeChat's voice calling feature that allows attackers to compromise both iOS and Android devices without user interaction. The flaw, discovered in September 2026, enables malware to spread simply by receiving a malicious call, granting full access to messages, contacts, and account controls. This zero-click exploit works across platforms, posing a widespread threat to WeChat's global user base.

The vulnerability lies in how WeChat processes incoming VoIP calls, where a specially crafted signal can trigger memory corruption leading to remote code execution. Once activated, the worm installs silently, harvesting personal data and propagating to the victim's contacts through automated malicious calls. Researchers demonstrated that no tap, approval, or interaction is required—the infection begins the moment the call connects. The attack leverages weaknesses in the app's real-time communication stack, bypassing standard security sandboxing on both Apple and Google mobile operating systems.

After initial infection, the malware scans the device's address book and initiates outgoing WeChat calls to selected contacts, using the compromised account to appear legitimate. Each successful call repeats the cycle, creating a self-replicating chain that can escalate rapidly across social networks. Unlike traditional phishing, this method avoids suspicious links or files, making detection difficult for users and security tools alike. The worm also exfiltrates chat histories, media files, and authentication tokens, potentially enabling identity theft or financial fraud. Researchers noted that the exploit remains effective even if the target has disabled unknown callers, as it abuses trusted WeChat channels.

Can Users Protect Themselves Without Waiting for a Patch?

While WeChat has been notified and is developing a fix, no public patch was available at the time of disclosure. Experts recommend temporarily disabling voice call permissions within the app settings as a precautionary measure, though this limits functionality. Users are advised to monitor for unusual account activity, such as unexpected logins or messages sent from their profile. Long-term mitigation depends on WeChat implementing stricter input validation and memory safeguards in its VoIP module. Until then, the flaw highlights the growing risk of zero-click attacks in widely used communication platforms, where trust in familiar interfaces can be exploited at scale. Frequently Asked Questions How does this worm differ from typical malware that requires user interaction? Unlike malware that relies on users clicking links or downloading files, this zero-click exploit activates automatically upon receiving a malicious WeChat call, requiring no action from the victim beyond the call connecting.

Is this vulnerability limited to specific regions or versions of WeChat? The flaw affects the core VoIP functionality present in global versions of WeChat on both iOS and Android, meaning users worldwide are potentially at risk regardless of location or language settings.

What data can attackers access once a device is infected? Compromised devices allow attackers to read messages, steal contacts, access media files, and hijack the WeChat account to send further malicious calls or impersonate the user in conversations.

Content written by Sead Fadilpašić for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment