A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target’s WeChat account in seconds without the victim having to answer the call.
Calif researchers said the bug was reported to Tencent in July. Tencent has fixed the issue for users, but the research warns how mobile messaging apps can be targets for attacks on a global level.
By infosecbulletin
/ Tuesday , September 8 2026
A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
By infosecbulletin
/ Tuesday , September 8 2026
A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
By infosecbulletin
/ Tuesday , September 8 2026
Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
By infosecbulletin
/ Monday , September 7 2026
Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
By infosecbulletin
/ Monday , September 7 2026
Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
By infosecbulletin
/ Monday , September 7 2026
Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
By infosecbulletin
/ Sunday , September 6 2026
CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
By infosecbulletin
/ Saturday , September 5 2026
Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
By infosecbulletin
/ Saturday , September 5 2026
India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
By infosecbulletin
/ Saturday , September 5 2026
Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
According to Calif’s public research listing, WeWorm is described as “the first zero-click worm to spread through WeChat calls across iOS and Android,” and it was published on September 8, 2026, as part of the company’s Android-tagged research work.
Calif sees the finding as a real example, not just a theory, of how a trusted messaging relationship can be abused. One hacked contact can start attacks on all their friends.
The company’s demo showed that three phones were used to test cross-platform connections. A Pixel 10a was the main attacker phone. It called an iPhone 17e and took advantage of a weakness while the call was ringing. The hacked iPhone then called another Pixel 10a, which was also taken over in the same way.
A wormable condition in a communications app means the attacker calls the victim, the victim then becomes the attacker, and the infection spreads easily. Click here to see the full report.
Related News:
Worm GPT for hackers, ‘No Ethical Boundaries or Limitations’
PlugX Malware Plagues Over 90k IP Addresses over 170 countries