HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Zero‑Click Worm Exploits WeChat Call Function to Hijack iPhone and Android Accounts

Researchers disclosed a zero‑click worm that can take over WeChat accounts on iOS and Android simply by receiving an incoming call from a trusted contact. The flaw bypasses user interaction, underscoring the need for robust vulnerability‑management and auditable remediation processes.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Zero‑Click Worm Exploits WeChat Call Function to Hijack iPhone and Android Accounts

What Happened — Researchers at Calif disclosed a zero‑click worm that can seize a WeChat account simply by receiving an incoming call from a trusted contact. The exploit works on both iOS and Android devices without any user interaction. Tencent was notified in July and has reportedly begun remediation.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of unpatched critical application flaws that can bypass traditional user‑centric defenses.
  • Highlights the need for continuous vulnerability‑management controls that capture, prioritize, and remediate zero‑day findings across third‑party software.
  • Provides a concrete example of why organizations must maintain auditable evidence of timely patching to satisfy multiple compliance regimes.

Who Is Affected

  • Consumers and enterprises that rely on WeChat for communication (messaging, payments, and mini‑programs).

Recommended Actions

  • Map this incident to your vulnerability‑management control objective and verify that you have a process for rapid triage of critical third‑party flaws.
  • Collect and retain evidence of patch status and remediation timelines to support audit readiness.
  • Monitor vendor advisories and apply updates as soon as they are released; consider compensating controls (e.g., network‑level call‑blocking for untrusted numbers) until patches are deployed.

Technical Notes – The worm leverages a flaw in the WeChat call‑handling stack that triggers code execution on receipt of a SIP‑style call payload. No CVE identifier has been published yet, but the vulnerability is classified as a remote code execution with a zero‑interaction requirement, effectively a “zero‑click” exploit. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →