A Zero-Click Worm Spreads Through Incoming Calls on WeChat, Leaving Millions Vulnerable
Millions of users of China’s dominant social media app WeChat have been put at risk after a zero-click worm took advantage of a vulnerability in the app to gain unauthorized access to their accounts. The malware, which spreads through incoming calls, has compromised iPhones and Android devices alike, highlighting the ongoing threat posed by exploit-based attacks.
The vulnerability was reportedly exploited through a combination of SMS spoofing and manipulation of WeChat’s built-in call-handling functionality. When an infected number is called, the app silently triggers a malicious payload, giving hackers unfettered access to the victim’s account without any interaction or consent required from the user. This type of attack is particularly insidious because it doesn’t require users to engage with the malware in any way, making it nearly impossible for them to detect.
The worm has reportedly affected millions of WeChat users, although the exact figure remains unclear due to a lack of transparency from the company. Users are typically unaware that their accounts have been compromised until they notice suspicious activity or receive notifications from WeChat about security breaches. This has led to widespread concern among users and cybersecurity experts alike, with many calling for greater accountability from the company in terms of protecting user data.
The vulnerability is also a reminder of the ongoing cat-and-mouse game between hackers and social media platforms like WeChat. As hackers continually develop new exploits, these companies must scramble to patch vulnerabilities before they can be used by malicious actors. This creates a never-ending cycle of attack and counterattack that puts users at risk in the middle.
The zero-click worm is also notable for its ability to bypass traditional security measures, including two-factor authentication (2FA) and antivirus software. This has significant implications for enterprises and organizations that rely on these measures as part of their cybersecurity strategy. It’s a stark reminder that no single solution can guarantee complete protection against sophisticated attacks.
For users of WeChat and other social media platforms, this incident serves as a timely reminder to remain vigilant about potential security threats. While it may not be possible to completely eliminate the risk of zero-click worms, there are steps you can take to minimize your exposure. This includes being cautious when receiving unsolicited calls or messages from unknown numbers, regularly monitoring your account activity for suspicious behavior, and ensuring that all software on your device is up-to-date with the latest security patches. By staying informed and taking proactive measures, users can better protect themselves against these types of attacks.
Source: The Hacker News — 2026-09-08