A Zero-Click Worm Spread Through WeChat Voice Calls

The demonstration required three phones and no cooperation from the victim. On a desk at a Palo Alto security firm, researchers placed a Pixel and an iPhone side by side and initiated a WeChat voice call to the iPhone. The phone was never answered. The call still did its work: a stream of data crossed into the iPhone, corrupted its memory, and turned the device into a relay that began dialing a third phone on its own.

The researchers named the weapon WeWorm. Built by Calif Research, a security firm based in Palo Alto, it exploits a memory-corruption flaw in the voice-over-internet stack that WeChat uses to carry calls, according to the firm’s disclosure. Because the attack requires no click, no link, and no answered call, the victim never sees or touches anything.

Calif Research disclosed the flaw on September 8, 2026, and said it affected both iOS and Android versions of WeChat. A phone compromised by the worm can be made to spread the infection onward through its own contact list, the researchers said, in the manner of the computer worms that swept through email systems decades ago, except carried silently through a voice channel.

Tencent, the company that owns WeChat, patched the flaw on its servers shortly after the disclosure, according to the researchers. The fix required no update to the app itself, because the vulnerable code sat on the network side of the call stack, which Tencent controls. That arrangement spared WeChat’s users from downloading a patch, but it also meant the flaw sat in infrastructure that Tencent, and not the user, had to fix.

The scale of the platform is what gives the flaw its weight. WeChat is not a niche messaging app; it is the default layer of daily life for a large share of China’s population, used for payments, identity, work, and conversation. A worm that can move through it without a click is a different category of threat from a phishing link that a careful user can simply refuse.

Zero-click attacks are the most prized tools in the surveillance trade. The commercial spyware sold by firms such as NSO Group has for years relied on flaws that require nothing from the target, and the prices those vendors charge reflect the difficulty of finding them. WeWorm shows the same class of weakness turning up in a consumer application used by roughly 1.3 billion people, a figure Tencent has cited.

The demo itself was modest in scale but precise in meaning. A Pixel attacked an iPhone, the iPhone dialed a third device, and the infection propagated without any of the three phones ever being unlocked or handled. The point was not to prove damage but to prove reach, and the chain of three devices was enough to establish that the worm could move on its own.

Memory-corruption flaws have been a persistent weakness in software that parses untrusted data, and voice code is a favored target because it runs continuously and handles data arriving from the network. When a program trusts the length of an incoming packet more than it should, an attacker can overwrite the memory that controls what the program does next. The researchers said the WeChat flaw fit that pattern.

Tencent has not commented publicly in detail, and the company did not dispute the findings in the disclosure. Server-side patches of this kind are attractive to a platform operator because they avoid the slow, uneven rollout of app updates, but they also mean the public often cannot verify that a fix has actually landed on the systems they use.

The disclosure followed the now-standard rhythm of coordinated vulnerability reporting: the researchers notified Tencent, waited while the fix was prepared and deployed, and published only after the patch was in place. The lag between discovery and disclosure, which the researchers did not specify, is the window in which such a flaw is most dangerous.

The broader lesson concerns the software that billions of people run without thought. Voice and video codecs sit at the bottom of the stack, written years ago and rarely audited, and they process the least trusted data a device ever receives: whatever arrives from the network. The researchers’ point was that a single such flaw, in the right application, can become a worm.

Calif Research has not said whether it found any indication that WeWorm was used in the wild before the patch, and the disclosure did not attribute the flaw to any actor. The absence of evidence of exploitation is not evidence of absence, and the researchers framed their work as a demonstration of possibility rather than a report of an attack that had already occurred.

What the episode makes plain is the asymmetry of the modern message stack. A billion users carry an application that can be reached silently, through a channel most of them consider harmless, and the only thing standing between them and a worm of this kind is the diligence of a handful of researchers and the speed of a server-side patch. That is a thin margin for a platform of WeChat’s reach.

For WeChat users, nothing changed on their screens. The patch arrived without an update, the worm never required their cooperation, and most of them will never learn that the threat existed. That silence is itself the story: the most consequential security event of the year for one of the world’s largest applications passed without a single user being asked to do anything at all.

Related Posts

  • September 23, 2026
  • 13 views
Hack VC’s Former Partner Found Dead in the California Desert

Hsin-Ju Chuang spent nearly a decade inside the crypto industry’s fastest-growing companies, including a stretch running growth at Solana. In the final weeks of her life, she had turned against…

  • September 23, 2026
  • 12 views
Microsoft and Partners Take Down Fraud Service Tied to 12,000 Accounts

The criminals behind the platform did not need to write their own code. For a subscription fee, “EvilTokens” sold them the tools to break into Microsoft accounts, a service built…