
Zero-Click WeChat Worm Hijacks Accounts Through Incoming Calls
Researchers from Calif demonstrated a zero-click worm that hijacks a WeChat account via an incoming call from a trusted contact, without the user answering. Once the exploit runs, the attacker can read and send messages, make calls, and act as the account owner, though only the account and not the device is compromised. Tencent patched the bug with Android/iOS updates and blocked the exploit on its servers; no real-world attacks have been reported. The attack relies on the caller being in the contact list, and full technical details will be released later.







