{
  "id": 6419687,
  "title": "WeChat worm could pwn a friend before they even answered the call",
  "url": "https://urgent.news/2026/09/09/wechat-worm-could-pwn-a-friend-before-they-even-answered-the-call",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-09T12:45:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/09/wechat-worm-could-pwn-a-friend-before-they-even-answered-the-call/5295234"
  },
  "original_language": "en",
  "account": null,
  "summary": "A zero-click vulnerability in WeChat's VoIP stack, dubbed WeWorm, has been discovered by researchers at Calif. This flaw, which affects both iOS and Android devices, allows a trusted contact to take control of a user's account simply by calling them, even before the recipient answers the call. The compromised account can then call other contacts and repeat the process without user interaction. Once exploited, the attacker can read and send messages, make calls, and act on behalf of the victim. Although Tencent has pushed fixes to address the attack, the researchers behind WeWorm are withholding key details. The vulnerability could potentially be chained with other Android and iOS bugs to compromise an entire device. The researchers argue that the exploit highlights the potential scale and severity of cyber threats as AI increases the capabilities of threat actors.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "WeChat worm could pwn a friend before they even answered the call",
        "url": "https://urgent.news/2026/09/09/wechat-worm-could-pwn-a-friend-before-they-even-answered-the-call-6423466",
        "published": "2026-09-09T12:45:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}