WeChat was exposed to an epic vulnerability: after making a voice call, the number was "lost"

📅 2026-09-11

Abstract:

Recently, security research organization Calif Research released an attack demonstration called WeWorm. To put it simply, an attacker only needs to make a WeChat voice call to you, and you don’t have to do anything. You don’t have to answer, click on a link, enter a password, or even have a verification code. Your WeChat account has already been hijacked while the phone is still ringing.



Even the hijacked account will automatically make a voice call to the next person, which can be broken through in the same way and spread in a chain like a worm. Android can hit Apple, and Apple can hit Android.

What’s so scary about this vulnerability?

The first is completely zero contact.

In the past, network attacks still required you to click on phishing links and read unknown files. This is better. As long as your phone rings, you have already been attacked.

The attacker has gained complete control over WeChat and can read your chat history, send messages and make calls in your name, which means your WeChat identity has been directly stolen.

Secondly, it is hard to guard against.

The vulnerability mechanism occurs during the ringing stage, and malicious data has entered WeChat's processing process before you answer the call. It is indeed possible to interrupt the attack by hanging up the phone, but you have to do it quickly, as it is essentially a race against time. If you choose to call when you are sleeping, by the time you touch your phone in a daze, you may be done long ago.

Even across brands.

General mobile phone vulnerabilities either only affect Android or only Apple. This worm can actually be transmitted back and forth between Android and iOS. True to its name, it crawls between devices.


However, it is said that it has been fixed in Android 8.0.77 and iOS 8.0.76. But obviously, WeChat will only tell you "Fixed some known issues."

The most surprising thing is that this vulnerability was discovered by AI. Calif's research team said their AI first discovered the vulnerability in July this year and then manually confirmed the exploit.

Fortunately, this vulnerability was discovered and reported by security researchers first.


In the comment area, a certified doctorate in information and communication engineering commented: WeChat's current code has piled up into a "hill of shit". If we still adhere to the "small but beautiful" route, the hidden zero-buffer vulnerability will sooner or later be exploited by black companies and make big news.

WeWorm may be just the beginning. WeChat is a national application used by more than one billion people. Behind every zero-click vulnerability is the information security of massive users.

In the end, the scariest thing about this vulnerability is that when a WeChat call comes, you don’t do anything. Just seeing the call, your account is gone. There is no need for you to click on the link, no need for you to enter the password, or no need for you to accept the link. The threshold for attack has been reduced to the lowest level.

What’s even more worth pondering is that it was AI that dug out this vulnerability. AI can already mine 0days automatically, and the pace of attack and defense will only get faster and faster in the future. AI can help good people plug loopholes, and it can also help bad people find loopholes. This double-edged sword is being sharpened faster and faster.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet