Security researchers at Calif report developing and testing a “zero-click” worm, dubbed WeWorm, that can take over WeChat accounts through an incoming call. They say the attack works without the person called answering or touching their device, provided the caller is already saved as a contact in the victim’s WeChat account.
Calif says it privately reported the underlying vulnerability to Tencent in July. According to the researchers, the worm then uses the compromised account’s stored contacts to propagate by placing similar calls to other users. The sources describe a demonstration in which the worm spreads across multiple test phones, with the researchers warning it could reach far more devices under real-world conditions.
Across the two outlets, the central details match: the infection occurs via a WeChat call, requires no user interaction from the recipient, and leverages contacts already present in WeChat to spread. The coverage differs mainly in emphasis—one highlights the takeover and demonstration on iOS and Android, while the other describes potential scale and the worm’s broader propagation behavior.