< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-08T17:24:29+05:30

WeChat Zero-Click Exploit Compromises Accounts via Unanswered Calls on iOS and Android

A zero-click exploit allowed a WeChat worm to take over accounts via unanswered calls on iOS and Android devices, with the vulnerability reported and mitigated by Tencent. The attack required the caller to be a WeChat contact and did not require user interaction, but Tencent patched the flaw in August 2026.

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones.

The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

Read original article

*** END OF TRANSMISSION ***