WeWorm: Zero-Click WeChat Worm
Security researchers have demonstrated 'WeWorm,' a zero-click exploit that can compromise WeChat accounts across iOS and Android devices simply by initiating a call. The exploit allows attackers to hijack accounts and spread the worm to the victim's contact list without any user interaction.
Why it matters
This highlights a critical vulnerability in widely used messaging platforms, posing a significant security risk to over a billion users globally.
The first zero-click worm to spread through WeChat calls across iOS and Android.
At Calif, our mission is to keep the Internet together by occasionally taking it apart. We believe everyone deserves a safe and secure Internet, including the people who cannot protect themselves.
Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. This is the first installment in a series exploring zero-click attack surfaces in mobile messaging apps.
WeChat is an "everything app" used by virtually everyone in China and by Chinese communities worldwide. Simply by calling a victim, WeWorm can hijack their account and call their friends, spreading from phone to phone. If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in