A call that could spread the attack

Security researchers at Calif disclosed on September 12, 2026, a demonstration of what they describe as the first zero-click worm capable of spreading through WeChat calls across both iOS and Android. Their laboratory chain moved from an Android phone to an iPhone and then to a second Android device, turning each compromised account into the launch point for the next call.

The victim did not have to answer or otherwise interact with the phone, according to the researchers. Exploitation occurred while the device was ringing and gave the team control of the affected WeChat account, including the ability to read and send messages, place calls and act as the user. Calif said declining a call stopped that particular attempt, though an attacker could try again later.

The demonstrated route depended on the caller already being on the target's WeChat friend list. That restriction could still enable worm-like propagation because a compromised friend account could call its own trusted contacts. Calif framed the result as a warning about how privileges granted to familiar accounts can become a distribution mechanism after one account is breached.

Tencent has mitigated the demonstrated exploit

Calif said it reported the vulnerability to Tencent in July and that Tencent has since mitigated the demonstrated exploit for all users. The disclosure therefore documents a security weakness and a controlled proof of concept, not an active outbreak. The researchers are withholding technical details of the memory-corruption issue in WeChat's voice-over-IP stack while related defensive work continues.

The team said it found the bug and produced the initial remote-code-execution exploit in roughly two days while working with AI, then spent another week building the worm. Those timings are the researchers' account of their own project, but they illustrate the central concern behind the disclosure: increasingly capable tools may shorten the path from vulnerability discovery to working exploitation.

Calif also cautioned that compromise of the WeChat account was not necessarily the end of a potential chain. When combined with separate operating-system vulnerabilities, the account-level route could contribute to wider device control. The disclosed WeChat flaw alone should not be read as proof that every targeted phone could be fully taken over.

The researchers plan to present a fuller analysis at a future conference and are examining unconventional attack surfaces in other messaging applications. Their immediate conclusion is that platform owners and app developers may need broader reductions in trusted, remotely reachable attack surfaces. For users, the most important verified point is narrower: the specific exploit Calif demonstrated has been reported and mitigated, while the design pattern it exposed remains a subject for industry review.