
highMalware
Researchers Demonstrate Zero-Click WeChat Worm Spreading via Incoming Calls
Researchers at the security firm Calif have demonstrated a zero-click worm that takes over WeChat accounts on iPhone and Android through incoming calls. The attack requires the caller to already be in the target's WeChat contact list. The target does not need to answer or interact with the phone. The flaw was reported to Tencent in July 2026. The demonstration involved three test phones, and Tencent's remediation status remains unconfirmed.
The Hacker News1 min read