Researchers at Calif discovered and privately reported a critical WeChat vulnerability that enabled them to build “WeWorm,” a worm that spreads through WeChat calls without any user interaction. The flaw let attackers compromise accounts and propagate across iOS and Android devices, prompting Tencent to release mitigations for the app and its servers. #WeChat #Tencent #WeWorm #Calif
Keypoints
- Calif researchers discovered a critical vulnerability in WeChat.
- The flaw was weaponized into a worm called WeWorm.
- WeWorm spreads through WeChat calls without user interaction.
- The worm can hijack accounts and use contacts to spread further.
- Tencent issued app updates and server-side mitigations after the report.
Read More: https://www.helpnetsecurity.com/2026/09/08/wechat-weworm-vulnerability-exploit-account-hijacking/