Skip to content
Tech News
← Back to articles

WeWorm: Zero-Click WeChat Worm

read original get YubiKey 5C NFC Security Key → more articles
Why This Matters

Security researchers at Calif have demonstrated WeWorm, a zero-click worm that spreads through WeChat voice calls on both iOS and Android, hijacking accounts in seconds without the victim answering or touching the phone. Because WeChat is an 'everything app' embedded in daily life for over a billion people, a self-propagating account takeover could cascade through social graphs and, chained with OS bugs, lead to full device compromise. It's a reminder that messaging apps' call-handling code remains a rich, underexamined attack surface.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — Stories like WeWorm are a reminder that your accounts are only as safe as their weakest login. The YubiKey 5C NFC adds a physical second factor for services that support it, working over USB-C or NFC tap with phones and laptops so a stolen password alone isn't enough.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

The first zero-click worm to spread through WeChat calls across iOS and Android.

At Calif, our mission is to keep the Internet together by occasionally taking it apart. We believe everyone deserves a safe and secure Internet, including the people who cannot protect themselves.

Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. This is the first installment in a series exploring zero-click attack surfaces in mobile messaging apps.

WeChat is an "everything app" used by virtually everyone in China and by Chinese communities worldwide. Simply by calling a victim, WeWorm can hijack their account and call their friends, spreading from phone to phone. If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide.

We built a demo worm with three phones:

The first Android phone, a Pixel 10a, is the attacker. We used it to call the second phone, an iPhone 17e, and exploited the bug to take over its WeChat while it was still ringing. We then used the compromised iPhone to call the third phone, another Pixel 10a, and took that one over the same way. Attacker calls victim, victim becomes attacker, victim calls the next victim.

You can also watch individual Android and iOS RCE demos.

Exploitation takes only seconds, and gives us full control of the WeChat account. We can read and send messages, make calls, and act on the victim's behalf. Chained with other Android and iOS bugs we've reported and are helping fix, it can lead to full control of the device.

The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. Declining the call stops that attempt, but the attacker can simply try again later, for example, while the victim is asleep.

This exploit requires the attacker to be on the victim's friend list. But that's not much of a barrier: an attacker can compromise one of your friends first and use their account to reach you.

... continue reading