Researchers from the security firm Calif have developed a zero-click worm that effectively compromises WeChat accounts on both iPhone and Android devices through incoming calls. This exploit requires no action from the recipient; merely being contacted by a WeChat connection is sufficient for the takeover to occur. The researchers reported this critical vulnerability to Tencent in July, highlighting an urgent need for enhanced security measures within the popular messaging platform.
For businesses relying on WeChat for communication, this discovery underscores the importance of robust cybersecurity practices and vigilance against potential exploitation. Organizations should consider implementing additional security layers, such as multi-factor authentication and user education on recognizing suspicious activity. This incident serves as a stark reminder of the evolving threat landscape, particularly in the realm of AI and cybersecurity, where seemingly harmless technologies can become conduits for sophisticated attacks. As cyber threats continue to advance, it is crucial for companies to stay informed and proactive in their defenses.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html)*