Skip to finding
§
High
Zero-click — WeChat
Confirmed

An incoming WeChat call from an existing contact can execute code and take over the recipient’s account without being answered.

The phone only has to ring; an existing contact is the gate.

Affects

WeChat, Tencent’s messaging and calling application on Android and iOS.

What it enables

Zero-click WeChat account takeover and contact-to-contact worm propagation

Control a WeChat account already listed in the victim’s contacts→↓Place a WeChat call to the victim→↓The recipient’s VoIP stack processes attacker-controlled data while the phone is ringing→↓Memory corruption yields code execution inside WeChat→↓Read and send messages, place calls as the victim and call further contacts to repeat the chain
Why this matters

A caller already trusted as a contact can turn one compromised account into the next calling point without action from the recipient.

Detail and 3 sources
Required access

An attacker-controlled WeChat account already present in the victim’s contacts, with internet reachability to place a call

Affected versions

WeChat 8.0.76 for Android (tested), WeChat 8.0.75 for iOS (tested), WeChat 8.0.76 for Android (demonstrated), WeChat 8.0.75 for iOS (demonstrated)

Proof of concept

Demonstrated by the researcher

While the phone rings, WeChat processes attacker-controlled VoIP data. Memory corruption yields application-context code execution, including the ability to read and send messages and place calls as the victim.

Researchers demonstrated the chain from a Pixel to an iPhone and onward to another Pixel without either call being answered. Tencent confirmed the finding and deployed client and server mitigations.

Mitigation coverage reaches end-of-life hardware, but pre-fix image acceptance and revocation completeness remain unresolved.

Evidence
Calif demonstrated propagation from a Pixel to an iPhone and back to another Pixel without answering either callTencent confirmed the remote-code-execution finding and deployed client and server mitigationsPublic exploit source or a trigger artifact is available
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 9, 2026