Zero-Click WeChat Worm Hijacks Accounts Through Incoming Calls

TL;DR Summary
Researchers from Calif demonstrated a zero-click worm that hijacks a WeChat account via an incoming call from a trusted contact, without the user answering. Once the exploit runs, the attacker can read and send messages, make calls, and act as the account owner, though only the account and not the device is compromised. Tencent patched the bug with Android/iOS updates and blocked the exploit on its servers; no real-world attacks have been reported. The attack relies on the caller being in the contact list, and full technical details will be released later.
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls thehackernews.com
- A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts The New York Times
- Calif security firm built AI-powered WeChat worm WeWorm qz.com
- Using AI, Calif Creates Demo WeChat Exploit that Spreads Through Phone Calls Security Boulevard
- "Zero-click" WeChat worm could hijack accounts and spread via a single call Help Net Security
Reading Insights
Total Reads
1
Unique Readers
8
Time Saved
4 min
vs 5 min read
Condensed
89%
808 → 92 words
Want the full story? Read the original article
Read on thehackernews.com