{
  "id": 6514413,
  "title": "Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls",
  "url": "https://urgent.news/2026/09/10/experts-build-wechat-worm-able-to-spread-across-millions-of-iphone",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-10T01:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/experts-build-wechat-worm-able-to-spread-across-millions-of-iphone-and-android-devices-via-phone-calls"
  },
  "original_language": "en",
  "account": "A team of researchers from California discovered a zero-click vulnerability in the WeChat VoIP system that allows malicious actors to take control of users' accounts on both Android and iOS devices. This flaw, dubbed \"WeWorm,\" takes advantage of a memory corruption issue within the VoIP stack to infiltrate a victim's device simply by making a phone call. The victim does not need to answer the call for the attack to occur; even a silent ringing call is sufficient for the worm to infect the device. Once inside, the attacker gains access to the victim's WeChat account, including messages, contacts, and other app data. Tencent patched the flaw in Android 8.0.77 and iOS 8.0.76, claiming that the issue has been mitigated on all affected devices. The researchers chose not to disclose the technical details of the flaw, instead demonstrating it at an upcoming conference. This isn't the first zero-click flaw found in modern smartphones, and it's likely to be the last. Tencent patched the vulnerability, but did not provide further details in their patch notes. The researchers plan to investigate similar flaws in other messaging apps and work with developers to reduce attack surfaces.",
  "summary": "Your phone rings, and you're infected - with all of your contacts and messages exposed.",
  "key_points": [
    "Researchers discover zero-click vulnerability in WeChat VoIP system.",
    "WeWorm exploits memory corruption to infect Android and iOS devices via phone calls.",
    "Tencent patched flaw in Android 8.0.77 and iOS 8.0.76, but details undisclosed."
  ],
  "editors_take": "This discovery highlights the vulnerability of popular messaging apps to zero-click exploits, allowing attackers to gain control of users' accounts and data with minimal interaction.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}