September 10, 2026 — If you use WeChat, you may have seen alarming headlines this week: a security flaw that lets an attacker hijack your account with a single voice call — no answer required. The vulnerability is real, but the good news is that Tencent has already fixed it — both on the server side and through app updates released in late August [citation:1][citation:7].

Here's everything you need to know about the WeWorm vulnerability, what Tencent has done to protect you, and why you should still update your app [citation:1][citation:9].

Quick Answer: Security firm Calif Research discovered a zero-click vulnerability in WeChat's VoIP stack that could allow an attacker to hijack a WeChat account simply by placing a voice call — without the victim answering or interacting with their phone [citation:1][citation:9]. Tencent fixed the flaw in client updates on August 21 (Android 8.0.77 / iOS 8.0.76) and completed server-side mitigation on August 28 [citation:3][citation:7]. Current WeChat versions (iOS 8.0.78 and above) include additional security enhancements [citation:6]. Users should update immediately if they haven't already.
Zero-Click Attack Vector Fixed August 21 (Client Update) Server-Side Mitigation Complete iOS 8.0.78 / Android 8.0.77+ No Evidence of In-the-Wild Exploitation

What Happened: A Phone Call That Could Hijack Your Account

The vulnerability, dubbed WeWorm by security firm Calif Research, was a memory corruption issue in WeChat's VoIP protocol stack — the code that handles incoming call setup and audio data [citation:3][citation:7].

What made this flaw particularly dangerous was its zero-click nature. According to Calif's demonstration [citation:1][citation:7]:

  • The attacker only needed to place a WeChat voice call to the victim
  • The victim did not need to answer the call or interact with their phone in any way
  • The exploit completed within seconds — while the phone was still ringing
  • After taking control, the attacker could read and send messages, make calls, and act as the victim
  • The compromised account could then call the victim's contacts and repeat the process, creating a worm-like chain of infection [citation:9][citation:10]

Calif demonstrated the attack using three phones: a Pixel 10a called an iPhone 17e, compromised it while the call was still ringing, and the infected iPhone then called another Pixel 10a and did the same thing [citation:1][citation:10].

Why the Contact Requirement Wasn't Much Protection

One mitigating factor was that the attacker needed to be on the victim's friends list. However, as Calif noted, this offered limited protection: once any account was compromised, the attacker could use that trusted connection to target all of the victim's contacts [citation:1][citation:9]. WeChat's built-in trust model — which treats contacts as legitimate call sources — actually worked in the attacker's favor [citation:3].


The Timeline: From Discovery to Fix

Calif Research used AI to find the vulnerability and develop the exploit. According to their disclosure, the entire process from discovery to working worm took about nine days — work that would previously have taken a larger team months to complete [citation:1][citation:7].

Here's the complete timeline of what happened [citation:1]:

Date Event
July 2026Calif's AI discovers the vulnerability
July 24, 2026Calif submits vulnerability report to Tencent
August 21, 2026Tencent releases WeChat 8.0.77 (Android) and 8.0.76 (iOS) with fix
August 28, 2026Tencent confirms server-side mitigation is live for all users
September 3, 2026Calif shares full technical analysis and exploit code with Tencent
September 4, 2026Tencent confirms vulnerability can be used for remote code execution
September 8, 2026Calif publishes public research article

Tencent told multiple media outlets that it had no evidence the vulnerability was ever exploited and no reason to believe any user accounts were affected [citation:8][citation:14].


What You Should Do Now

Even though Tencent has mitigated the threat on its servers, there are still good reasons to update your WeChat app [citation:3][citation:7].

Step 1: Check Your Version and Update

The minimum safe versions are:

  • iOS: WeChat 8.0.76 or later
  • Android: WeChat 8.0.77 or later

According to IT之家, WeChat iOS version 8.0.78 is now available on the App Store. The official release notes describe the update as “fixing some known issues,” but security enhancements are included [citation:6][citation:12].

Important: Tencent's server-side mitigation means the vulnerability is blocked even on older app versions [citation:3][citation:7]. However, updating your app ensures you have the latest security protections and fixes for other potential vulnerabilities. It's always good practice to stay current.

Step 2: Check for Suspicious Activity

If you notice any of the following, take immediate action [citation:7]:

  • Unexplained login attempts or new devices on your account
  • Messages you didn't send appearing in your chats
  • Calls to contacts you didn't make
  • Friends receiving calls from you that you didn't initiate

If any of these occur, change your WeChat password immediately and review your logged-in devices in “Account & Security” settings.

Step 3: Stay Informed

Calif Research plans to present a full technical analysis of the vulnerability at an upcoming security conference [citation:1][citation:3]. For now, the immediate threat is contained — but this incident highlights broader questions about AI-assisted vulnerability discovery and the speed at which exploits can be developed in 2026 [citation:3].

The Bigger Picture: AI and Cybersecurity

The WeWorm disclosure is significant not just for what it revealed about WeChat, but for how quickly it was developed. Calif said AI helped find the vulnerability in about two days and build the worm in another week — work that would previously have required a larger team and months of effort [citation:1][citation:7]. As AI tools become more accessible, the time between vulnerability discovery and weaponization is shrinking. The response — rapid disclosure, swift patching, and transparent communication — is becoming more critical than ever [citation:3][citation:10].


Key Takeaways

# What You Need to Know About the WeChat WeWorm Vulnerability
1Zero-click vulnerability confirmed — attackers could hijack WeChat accounts by placing a voice call, without the victim answering [citation:1][citation:9]
2Tencent fixed it quickly — client patches released August 21, server-side mitigation completed August 28 [citation:3][citation:7]
3No evidence of exploitation — Tencent says it has no reason to believe any users were affected [citation:8][citation:14]
4Update your app anyway — iOS 8.0.76+ and Android 8.0.77+ are safe; iOS 8.0.78 is now available [citation:6][citation:12]
5AI changed the timeline — vulnerability discovery and worm development took about 9 days, far faster than previously possible [citation:1][citation:7]
6Server-side mitigation protects everyone — even users who haven't updated are protected by Tencent's server-side fixes [citation:3][citation:13]
The Bottom Line: The WeChat WeWorm vulnerability was serious — a zero-click attack that could hijack accounts through a simple voice call. But Tencent's rapid response — both client patches and server-side mitigation — has contained the threat. No evidence suggests any users were affected. That said, this incident is a reminder: update your apps, pay attention to security news, and know that AI is changing the speed at which vulnerabilities are discovered and exploited. Staying informed is your best defense.
Sources and Methodology (as of September 10, 2026):
  • 快科技 / 太平洋科技 — WeWorm vulnerability details, zero-click nature, attack demonstration [citation:1]
  • Cloud Security Alliance — Technical analysis, AI-assisted discovery timeline, server-side mitigation [citation:3]
  • TechWeb — Vulnerability timeline, contact requirement limitations [citation:7]
  • 联合早报 — Tencent official statement, no evidence of exploitation [citation:8]
  • The Register — Attack mechanics, cross-platform propagation [citation:9]
  • eSecurity Planet — Attack demonstration, theoretical reach [citation:10]
  • IT之家 — WeChat iOS 8.0.78 update details [citation:6]
  • 今日头条 — iOS 8.0.78 release notes and version details [citation:12]
  • Kuwait Times / AFP — Tencent statement, AI-assisted development context [citation:14]
Published: September 10, 2026. WeChat vulnerability discovered July 2026, client patches released August 21, server-side mitigation completed August 28. Current safe versions: iOS 8.0.76+ (8.0.78 recommended), Android 8.0.77+.