WeChat Zero-Click Vulnerability Fixed: What You Need to Know and Why You Should Update
September 10, 2026 — If you use WeChat, you may have seen alarming headlines this week: a security flaw that lets an attacker hijack your account with a single voice call — no answer required. The vulnerability is real, but the good news is that Tencent has already fixed it — both on the server side and through app updates released in late August [citation:1][citation:7].
Here's everything you need to know about the WeWorm vulnerability, what Tencent has done to protect you, and why you should still update your app [citation:1][citation:9].
What Happened: A Phone Call That Could Hijack Your Account
The vulnerability, dubbed WeWorm by security firm Calif Research, was a memory corruption issue in WeChat's VoIP protocol stack — the code that handles incoming call setup and audio data [citation:3][citation:7].
What made this flaw particularly dangerous was its zero-click nature. According to Calif's demonstration [citation:1][citation:7]:
- The attacker only needed to place a WeChat voice call to the victim
- The victim did not need to answer the call or interact with their phone in any way
- The exploit completed within seconds — while the phone was still ringing
- After taking control, the attacker could read and send messages, make calls, and act as the victim
- The compromised account could then call the victim's contacts and repeat the process, creating a worm-like chain of infection [citation:9][citation:10]
Calif demonstrated the attack using three phones: a Pixel 10a called an iPhone 17e, compromised it while the call was still ringing, and the infected iPhone then called another Pixel 10a and did the same thing [citation:1][citation:10].
One mitigating factor was that the attacker needed to be on the victim's friends list. However, as Calif noted, this offered limited protection: once any account was compromised, the attacker could use that trusted connection to target all of the victim's contacts [citation:1][citation:9]. WeChat's built-in trust model — which treats contacts as legitimate call sources — actually worked in the attacker's favor [citation:3].
The Timeline: From Discovery to Fix
Calif Research used AI to find the vulnerability and develop the exploit. According to their disclosure, the entire process from discovery to working worm took about nine days — work that would previously have taken a larger team months to complete [citation:1][citation:7].
Here's the complete timeline of what happened [citation:1]:
| Date | Event |
|---|---|
| July 2026 | Calif's AI discovers the vulnerability |
| July 24, 2026 | Calif submits vulnerability report to Tencent |
| August 21, 2026 | Tencent releases WeChat 8.0.77 (Android) and 8.0.76 (iOS) with fix |
| August 28, 2026 | Tencent confirms server-side mitigation is live for all users |
| September 3, 2026 | Calif shares full technical analysis and exploit code with Tencent |
| September 4, 2026 | Tencent confirms vulnerability can be used for remote code execution |
| September 8, 2026 | Calif publishes public research article |
Tencent told multiple media outlets that it had no evidence the vulnerability was ever exploited and no reason to believe any user accounts were affected [citation:8][citation:14].
What You Should Do Now
Even though Tencent has mitigated the threat on its servers, there are still good reasons to update your WeChat app [citation:3][citation:7].
Step 1: Check Your Version and Update
The minimum safe versions are:
- iOS: WeChat 8.0.76 or later
- Android: WeChat 8.0.77 or later
According to IT之家, WeChat iOS version 8.0.78 is now available on the App Store. The official release notes describe the update as “fixing some known issues,” but security enhancements are included [citation:6][citation:12].
Step 2: Check for Suspicious Activity
If you notice any of the following, take immediate action [citation:7]:
- Unexplained login attempts or new devices on your account
- Messages you didn't send appearing in your chats
- Calls to contacts you didn't make
- Friends receiving calls from you that you didn't initiate
If any of these occur, change your WeChat password immediately and review your logged-in devices in “Account & Security” settings.
Step 3: Stay Informed
Calif Research plans to present a full technical analysis of the vulnerability at an upcoming security conference [citation:1][citation:3]. For now, the immediate threat is contained — but this incident highlights broader questions about AI-assisted vulnerability discovery and the speed at which exploits can be developed in 2026 [citation:3].
The WeWorm disclosure is significant not just for what it revealed about WeChat, but for how quickly it was developed. Calif said AI helped find the vulnerability in about two days and build the worm in another week — work that would previously have required a larger team and months of effort [citation:1][citation:7]. As AI tools become more accessible, the time between vulnerability discovery and weaponization is shrinking. The response — rapid disclosure, swift patching, and transparent communication — is becoming more critical than ever [citation:3][citation:10].
Key Takeaways
| # | What You Need to Know About the WeChat WeWorm Vulnerability |
|---|---|
| 1 | Zero-click vulnerability confirmed — attackers could hijack WeChat accounts by placing a voice call, without the victim answering [citation:1][citation:9] |
| 2 | Tencent fixed it quickly — client patches released August 21, server-side mitigation completed August 28 [citation:3][citation:7] |
| 3 | No evidence of exploitation — Tencent says it has no reason to believe any users were affected [citation:8][citation:14] |
| 4 | Update your app anyway — iOS 8.0.76+ and Android 8.0.77+ are safe; iOS 8.0.78 is now available [citation:6][citation:12] |
| 5 | AI changed the timeline — vulnerability discovery and worm development took about 9 days, far faster than previously possible [citation:1][citation:7] |
| 6 | Server-side mitigation protects everyone — even users who haven't updated are protected by Tencent's server-side fixes [citation:3][citation:13] |
- 快科技 / 太平洋科技 — WeWorm vulnerability details, zero-click nature, attack demonstration [citation:1]
- Cloud Security Alliance — Technical analysis, AI-assisted discovery timeline, server-side mitigation [citation:3]
- TechWeb — Vulnerability timeline, contact requirement limitations [citation:7]
- 联合早报 — Tencent official statement, no evidence of exploitation [citation:8]
- The Register — Attack mechanics, cross-platform propagation [citation:9]
- eSecurity Planet — Attack demonstration, theoretical reach [citation:10]
- IT之家 — WeChat iOS 8.0.78 update details [citation:6]
- 今日头条 — iOS 8.0.78 release notes and version details [citation:12]
- Kuwait Times / AFP — Tencent statement, AI-assisted development context [citation:14]
- WeChat vulnerability
- WeWorm
- zero-click attack
- Tencent security fix
- WeChat update
- VoIP vulnerability
- AI cybersecurity
- mobile security
- Gzmato
