WeChat in broken mirror showing zero-click attack

WeChat Zero-Click Attack Enables Account and Device Takeover Without User Interaction

AI security team Calif warns that a new zero-click attack method could allow a malicious actor to take over a victim’s WeChat account without any user interaction.

Tencent’s Weixin and WeChat have over 1.4 billion monthly active users, making the platform a lucrative target for cybercriminals.

Dubbed WeWorm, the remote code execution (RCE) vulnerability stems from a memory corruption flaw in the WeChat VoIP stack and affects both iOS and Android.

WeChat zero-click attack could take over iOS and Android devices

The cybersecurity team warned that the zero-click flaw could be chained with other security vulnerabilities to compromise the entire device. Chained with other vulnerabilities such as OEMpocalypse, the zero-click attack could enable an attacker to gain root access by exploiting other apps.

However, the researchers did not disclose which vulnerabilities could be chained with the WeChat zero-click vulnerability to compromise the device.

In corporate environments, attackers could pivot to other enterprise systems or even the broader IT network, potentially leading to more serious attacks, including ransomware.

“Chained with other Android and iOS bugs we’ve reported and are helping fix, it can lead to full control of the device,” the researchers said.

According to Calif, the attacker could execute the zero-click attack simply by calling the victim, who need not answer. The research team used three phones, including an iPhone 17e and Google’s own Pixel 10a, which were compromised while still ringing, as a proof of concept.

Upon taking over the victim’s WeChat account, the attacker can target other friends on the list, essentially creating a self-propagating worm. The attacker can also perform other actions on behalf of the victim, including reading and sending messages and making calls.

“Exploitation takes only seconds, and gives us full control of the WeChat account,” Calif wrote. “We can read and send messages, make calls, and act on the victim’s behalf.”

However, the attacker must be on the victim’s friends list. The zero-click attack also works if the victim answers the call or lets it continue ringing. However, declining the call stops the attack.

Nevertheless, the attacker could target the victim when they are away from their phone or could repeatedly call the target until the victim ignores the call. The human tendency to answer calls from friends, without knowing whether those contacts have been compromised, could also result in a zero-click attack.

“WeWorm fires while the phone is still ringing,” reiterated Jacob Krell, Senior Director, Secure AI Solutions & Cybersecurity at Suzu Labs. “The victim doesn’t answer, doesn’t tap anything, and it doesn’t matter. Once it takes over a WeChat account, it calls the victim’s contacts and repeats the cycle, spreading one friend list at a time. Declining the call blocks one attempt, but the attacker can retry while the victim sleeps.”

Consequently, the zero-click attack could become a handy tool for surveillance, fraud, identity theft, cyberoffense, and lateral propagation.

According to Calif, AI helped in discovering the vulnerability and developing the exploitation code within two days, underscoring AI’s growing role in cybersecurity.

“The most interesting part of the WeChat exploit isn’t the bug; rather, it’s the timeline,” said Ted Miracco, CEO of Approov. “It took only two days from the AI-discovered vulnerability to a working RCE, and one more week to a cross-platform worm.

“Work that used to take a competent team weeks or months. This speed to exploit collapses the assumption underlying patch-cycle security: that the window between bug discovery and weaponization gives defenders room to ship a fix and get it adopted.”

AI models have proven their capability to escape their sandboxes, enabling malicious actors to carry out malicious actions. Previously, malicious actors have leveraged AI to identify software bugs and develop exploitation scripts.

“The economics shift is staggering in regards to AI vulnerability discovery,” said Krell. “In 2019, NSO Group exploited CVE-2019-3568, a buffer overflow in WhatsApp’s Voice-over-IP (VoIP) stack, to deliver Pegasus spyware through the same missed-call pattern. That required $60 million a year in R&D and over 200 engineers from Israeli military intelligence. Calif built WeWorm with AI doing most of the heavy lifting in two days, their engineers providing the judgment on what to target and how to test safely.”

In May 2026, Google warned that hackers leveraged AI to discover a zero-day 2FA bypass vulnerability in a popular open-source web-based administration tool.

Tencent fixes zero-click vulnerability in WeChat

Meanwhile, Tencent has fixed the WeChat zero-click attack vulnerability on August 21, 2026. Calif had reported the bug to Tencent in July 2026 and also notified the White House. The company also says the vulnerability has been mitigated on the server side for all WeChat users. While the company has yet to disclose key details, it says there is no evidence that the vulnerability was exploited in the wild.

Super apps like WeChat are a lucrative target for cybercriminals because of their large user bases and advanced functionality, including mobile payments, banking and financial services, government services, delivery services, and mini-programs that run within them.

“WeChat handles payments, government services, and business communications for 1.439 billion users,” added Krell. “Compromising an account is closer to stealing someone’s digital identity than reading their texts.”