A WeChat call from an existing contact can execute code, take over the account and propagate without being answered.
Attacker-controlled VoIP data reaches the vulnerable path while the phone is still ringing.
WeChat, Tencent's mobile messaging and calling application on iOS and Android.
Zero-click cross-platform code execution, account takeover, and wormable propagation
The chain turns an existing contact relationship into a no-interaction propagation path across iOS and Android.
Detail and 2 sources
A compromised friend account places the crafted call; pre-answer processing triggers memory corruption, code execution and account control.
Researchers demonstrated the full chain across three physical devices, including onward calls from a newly compromised account.
Updated clients and Tencent’s server-side block are the documented mitigations. We do not know whether every underlying root cause was removed.
- access:network:internet
- reachable from the public internet
- access:credential:valid-user
- valid user credentials
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- Yes
This establishes deployment of a server-side block against the demonstrated exploit, not removal of the underlying client-side memory-corruption flaw.