An incoming WeChat call from an existing contact can execute code and take over the recipient’s account without being answered.
The phone only has to ring; an existing contact is the gate.
WeChat, Tencent’s messaging and calling application on Android and iOS.
Zero-click WeChat account takeover and contact-to-contact worm propagation
A caller already trusted as a contact can turn one compromised account into the next calling point without action from the recipient.
Detail and 3 sources
While the phone rings, WeChat processes attacker-controlled VoIP data. Memory corruption yields application-context code execution, including the ability to read and send messages and place calls as the victim.
Researchers demonstrated the chain from a Pixel to an iPhone and onward to another Pixel without either call being answered. Tencent confirmed the finding and deployed client and server mitigations.
Mitigation coverage reaches end-of-life hardware, but pre-fix image acceptance and revocation completeness remain unresolved.
- access:network:internet
- reachable from the public internet
- access:credential:valid-user
- valid user credentials
- interaction:none
- no user action required
- state:device:powered-on-idle
- device powered on and idle
- Reaches end-of-life hardware
- Yes
The evidence establishes global mitigation of the demonstrated exploit, but not removal of the underlying client vulnerability.