Skip to content

Security4 publishers3 min readPublished

Researchers built a WeChat worm that hijacks accounts while the phone is still ringing

Calif's WeWorm abused a memory corruption bug in WeChat's VoIP stack to take over accounts on an iPhone 17e and two Pixel 10a handsets, and Tencent blocked it server-side on 28 August without publishing an advisory or a CVE.

The Watch · Security desk

Photograph accompanying Researchers built a WeChat worm that hijacks accounts while the phone is still ringing
Photo: cyberinsider.com

What happened

  • Calif built WeWorm, a proof-of-concept worm that exploits a memory corruption bug in WeChat's VoIP stack and takes over an account through an incoming call the victim never answers or touches.
  • In the demo, a Pixel 10a called an iPhone 17e and seized its WeChat while the handset was still ringing, then the compromised iPhone called a second Pixel 10a and did the same to it.
  • Exploitation finishes within seconds and hands the attacker full control of the WeChat account: reading and sending messages, placing calls, and acting as the account's owner.
  • Tencent shipped WeChat 8.0.77 for Android and 8.0.76 for iOS on 21 August, and Calif confirmed on 28 August that the exploit was also blocked on Tencent's servers for all users.
  • As of 8 September there was no CVE identifier for the flaw and no advisory on Tencent's security response site, and neither company has said which WeChat versions were vulnerable.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Without an affected-version list, an operator cannot establish whether a handset was exposed in July or August, and with no published indicators there is no way to test whether a call was ever placed at one. The only assurance available is Tencent's server-side block.
  • exposure The WeChat builds for HarmonyOS, Windows, Mac and Linux ship on separate schedules and sit outside what has been confirmed fixed, because neither Calif nor Tencent has said whether the VoIP flaw reached them.
  • capability The friend-list requirement prices the first victim, not the campaign: each hijacked account becomes an authorised caller for everyone in its contact list, so contact-list membership behaves like a privilege an attacker can acquire.
  • contradiction Calif's AI-speed argument rests on a nine-day figure its own dated log stretches to 19, so how much of the capability-democratisation case you accept depends on which set of numbers the firm defends at disclosure.

Memory corruption in the VoIP stack, reached by placing a call [1]. The exploit runs while the handset rings and completes in seconds [6]. Picking up does not interrupt it, and the person who answers hears nothing [2]. Declining ends that attempt only; per Calif, the attacker calls back later, for example while the target is asleep [2].

The one gate is membership of the victim's WeChat friend list [3]. Calif built the demo to show that the gate opens from the inside: "an attacker can compromise one of your friends first and use their account to reach you," the researchers wrote, and the extra trust WeChat extends to contacts then works for the attacker [4]. The chain ran once in the lab, from a Pixel 10a to an iPhone 17e and on to a second Pixel 10a [5].

On its own, the bug takes the account, not the phone [7]. Calif says it can be chained with separate Android or iOS vulnerabilities to reach broader device control [7], and The Hacker News notes that Calif's post describes routes an attacker could use rather than routes it tested [8]. Nothing published shows the worm crossing out of WeChat into the handset. What it does show is a self-propagating account takeover, and for many users that account holds payments, official accounts and mini programs inside the same app [27].

Calif dates its own work: the engineering team knew of the bug on 23 July, finished an Android exploit on 30 July, an iOS exploit on 2 August, and a cross-platform worm demo on 11 August [9][10]. That is 19 calendar days from bug to worm [25]. The public framing is about two days from discovery to first RCE with AI help, plus another week for the worm, or roughly nine [11]; the post does not say whether the shorter figures count working time only [12]. Tencent's client releases landed 29 days after the 23 July date, and the server-side block was confirmed at 36 [26]. Calif shared its complete analysis and working exploits with Tencent on 3 September, after both [15].

Tencent reported 1.439 billion combined monthly active users for Weixin and WeChat as of 30 June 2026 [22]. Calif's report says actors "can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide" [23], and the firm says it published to push governments and technology companies toward cooperation on AI security [24]. Tencent's own contribution to the record is thinner: the iOS release notes and App Store entry describe 8.0.76 as bug fixes, and the most recent post on its security response site is dated April 2022 [17]. No attacks using the flaw have been reported, and Calif does not claim any [21].

Seven days from bug awareness to a working Android RCE against a widely deployed VoIP stack is the figure in Calif's timeline that stands whatever share of the credit AI gets [31].

What to watch

  • Whether Tencent publishes affected WeChat versions or requests a CVE, which would let users establish exposure for July and August.
  • Calif's promised conference analysis, the first material that would give defenders something searchable.
  • Calif says it is examining the same attack surface in other messaging apps and working with their developers; the next disclosure sets the pattern.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories