Researchers at the security firm Calif discovered a zero-click worm affecting WeChat that spreads through incoming calls on both iPhone and Android devices. The worm takes over user accounts without requiring the target to answer or interact with their phone in any way. The only prerequisite is that the caller must already exist as a contact in the victim's WeChat app.
Calif demonstrated the worm's propagation across three test devices, proving the vulnerability works in real-world conditions. The attack exploits a flaw in how WeChat processes incoming call signals. Because the mechanism operates at the network level rather than requiring user interaction, victims remain unaware of compromise until after account takeover occurs.
This vulnerability represents a severe threat to WeChat's 1.3 billion monthly active users. WeChat functions as the primary communication, payment, and identity verification platform across mainland China, Hong Kong, and Taiwan. Account compromise exposes users to financial theft, identity fraud, and social engineering attacks. For businesses operating in these regions, compromised WeChat Work accounts could enable lateral movement into corporate networks and data exfiltration.
The attack chain works because the vulnerability exists in WeChat's call handling mechanism before the user interface layer. Traditional security advice to avoid clicking suspicious links or opening malicious files becomes irrelevant here. The worm propagates purely through network protocols triggered by incoming calls. Each infected device automatically attempts to call other contacts in its list, creating an exponential spread pattern.
Calif reported the vulnerability to Tencent in July 2024. The company did not immediately disclose a patch release timeline in the initial disclosure, though Tencent acknowledged receipt of the report. Security researchers typically allow vendors 90 days to develop and release fixes before public disclosure. The timeline suggests a patch may arrive by October 2024, but users should verify Tencent's official announcements.
The technical sophistication of this worm exceeds typical mobile malware. Most mobile attacks require user interaction or system-level permissions. Zero-click vulnerabilities that leverage network protocols occupy the top tier of mobile exploit difficulty. Only nation-state actors and elite security researchers typically develop exploits of this caliber. The fact that a private security firm built a working proof-of-concept demonstrates the vulnerability's straightforward exploitation.
Users cannot currently block this attack through behavioral changes alone. Standard protective measures like disabling notifications or screening calls provide no defense against zero-click vectors. The only effective mitigation is a software patch from Tencent that closes the underlying flaw in call processing logic.
For organizations with WeChat Work deployments, this vulnerability creates immediate risk. Company accounts with financial or administrative authority face heightened exposure. Security teams should contact Tencent for patch availability and test updates in staging environments before deployment. In the interim, organizations may consider restricting WeChat Work access from personal devices and limiting call permissions through enterprise controls, if available.
Users relying on WeChat for payments or identity verification should monitor account activity for signs of unauthorized access. Unusual login locations, changed recovery contact information, or suspicious transaction history warrant immediate password resets and potential account recovery procedures through Tencent support.
