Skip to finding
§
High
Zero-click messaging
Confirmed

A WeChat call from an existing contact can execute code, take over the account and propagate without being answered.

Attacker-controlled VoIP data reaches the vulnerable path while the phone is still ringing.

Affects

WeChat, Tencent's mobile messaging and calling application on iOS and Android.

What it enables

Zero-click cross-platform code execution, account takeover, and wormable propagation

Attacker controls a WeChat account already on the target's friend list.→↓Attacker initiates a crafted WeChat voice call.→↓The recipient's client processes attacker-controlled VoIP data before the call is answered.→↓The flaw yields code execution and control of the recipient's WeChat account.→↓The compromised account calls its own contacts, repeating the chain without their interaction.
Why this matters

The chain turns an existing contact relationship into a no-interaction propagation path across iOS and Android.

Detail and 2 sources
Required access

Internet access and a WeChat account already present on the target's friend list; the recipient need not answer or interact with the call.

Affected versions

WeChat 8.0.76 for Android (demonstrated vulnerable), WeChat 8.0.75 for iOS (demonstrated vulnerable); the complete affected range is not public

Proof of concept

Demonstrated by the researcher

A compromised friend account places the crafted call; pre-answer processing triggers memory corruption, code execution and account control.

Researchers demonstrated the full chain across three physical devices, including onward calls from a newly compromised account.

Updated clients and Tencent’s server-side block are the documented mitigations. We do not know whether every underlying root cause was removed.

Evidence
Calif demonstrated the full chain across three physical iOS and Android devicesIndependent reporting corroborated the tested and mitigating client versions and Tencent's server-side blockTencent has not publicly documented the underlying defect or confirmed that every root cause was removed
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026