Researchers have weaponized a zero-click vulnerability in WeChat to create a self-propagating worm capable of hijacking user accounts and spreading via incoming VoIP calls.
Security researchers at Calif uncovered the vulnerability within WeChat’s VoIP stack and privately reported the flaw to Tencent. The resulting proof-of-concept worm, dubbed WeWorm, bypasses user interaction entirely, propagating automatically across saved contacts whether the recipient answers or ignores the incoming call.
According to the research team, the worm is platform-agnostic, capable of hopping between devices running iOS and Android. Exploitation occurs within seconds, granting complete control over the compromised WeChat account to execute actions on behalf of the victim.
“Simply by calling a victim, WeWorm can hijack their account and call their friends,” the Calif researchers stated. “Exploitation takes only seconds, and gives us full control of the WeChat account. We can read and send messages, make calls, and act on the victim’s behalf. Chained with other Android and iOS bugs we’ve reported and are helping fix, it can lead to full control of the device.”
The research team utilized artificial intelligence tools to identify the memory corruption issue and develop the initial remote code execution exploit within two days, constructing the complete worm in approximately one week. Tencent subsequently mitigated the bug by releasing updated versions of the WeChat app for iOS and Android, alongside server-side exploit mitigations.
“We are publishing our findings to raise public awareness,” the researchers noted. “These capabilities have existed for a long time in the hands of well-funded, sophisticated actors. What’s different now is that AI is putting these capabilities in the hands of less skilled actors, leaving ordinary users at unprecedented risk.”