WeChat Worm Used Trusted Calls to Jump Accounts

Calif showed a working WeChat worm that took over iPhone and Android accounts through incoming calls from existing contacts, and says Tencent later blocked the exploit. The demo spread across three test phones, and the company shipped mitigating versions 8.0.77 for Android and 8.0.76 for iOS on August 21. The trigger was a call from someone already on the victim's WeChat contact list. The target did not have to answer or tap anything; the attack could run while the phone was ringing, and once one account was taken the compromised contact could be used to reach the next one. That gives the attacker control of the account itself — messages, calls, and impersonation — but not the phone operating system. For organizations that rely on WeChat for communications or payments, the exposure sits in the social graph and account layer, not the device layer. Tencent says the exploit is blocked, and there is no report of in-the-wild abuse, but any account taken from a trusted contact could still be the start of a wider chain if the same trust pattern exists elsewhere.

Part of the PlainSec briefing for 2026-09-09

Editions

Sources