Security researchers have disclosed a severe, self-propagating vulnerability in WeChat that compromises accounts via a zero-click incoming call.
According to a report from The Hacker News, researchers at security firm Calif revealed a proof-of-concept exploit allowing an attacker to seize control of a target's WeChat account without any interaction from the victim. The attack is triggered the moment the victim receives a call from the attacker, requiring no answer, touch, or notification engagement.
A critical prerequisite for the attack is that the attacker must already be a contact within the victim's WeChat account. This initial foothold enables the exploit's most dangerous characteristic: its ability to self-propagate as a worm.
In their demonstration, Calif showed how the exploit could automatically spread. Once the first account was compromised, the worm used it to initiate calls to other contacts in that account's list, compromising them in a chain reaction. The researchers successfully tested this worm behavior across three phones, compromising accounts on both iOS and Android platforms.
This self-replicating mechanism elevates the threat from a targeted account takeover to a potential network-wide infection within an organization's communication chain. For enterprises, especially those with Bring Your Own Device (BYOD) policies or teams relying on WeChat for business coordination, a single compromised device could rapidly lead to widespread data exposure or internal fraud.
The vulnerability was disclosed to Tencent in July 2026. According to the Calif researchers, Tencent has since patched the specific flaw exploited in their proof-of-concept. However, the timeline and global rollout status of the patch for all users are critical factors in mitigating risk, as enforcement across a massive, fragmented user base remains a persistent challenge.
For IT teams, this incident underscores several immediate priorities. First, ensuring all WeChat clients—across both corporate and personal devices used for work—are updated to the latest version is essential. Second, organizations should review the role of WeChat in official workflows, considering whether alternative, more secure communication channels are warranted for sensitive discussions. Finally, the use of Mobile Device Management (MDM) solutions becomes more relevant to enforce application updates and potentially control which communication apps are permitted on corporate networks.
While the researchers did not observe widespread real-world exploitation, the public demonstration of a functional, self-propagating worm for a platform with WeChat's massive user base provides a clear template for malicious actors. The incident moves beyond a simple software bug, illustrating a scalable attack model for ubiquitous communication apps that blurs the line between personal and corporate security.
網絡安全研究人員披露微信存在一個嚴重的、可自我傳播的漏洞,攻擊者可透過零點擊來電方式入侵帳戶。
根據《黑客新聞》的報導,網絡安全公司 Calif 的研究人員揭示了一個概念驗證漏洞利用程式,攻擊者無需受害者進行任何互動,即可奪取目標微信帳戶的控制權。該攻擊在受害者接到攻擊者來電時即被觸發,無需接聽、觸摸或處理任何通知。
此次攻擊的一個關鍵前提是,攻擊者必須已存在於受害者的微信聯絡人名單中。這個初始立足點使得該漏洞最具危險性的特質得以展現:其作為蠕蟲自我傳播的能力。
在其示範中,Calif 展示了此漏洞如何自動擴散。一旦第一個帳戶被入侵,蠕蟲便利用它向該帳戶聯絡人名單中的其他成員發起通話,透過連鎖反應入侵這些帳戶。研究人員在三部手機上成功測試了此蠕蟲行為,成功入侵了 iOS 和 Android 平台的帳戶。
這種自我複製機制將威脅從針對性的帳戶接管,提升為可能在企業通訊鏈中引發的全面感染。對於企業,尤其是那些實施自攜裝置(BYOD)政策或依賴微信進行業務協調的團隊而言,單一設備被入侵可能迅速導致大規模的數據洩露或內部詐騙。
該漏洞已於2026年7月通報予騰訊。據 Calif 研究人員稱,騰訊隨後已修補了他們在概念驗證中利用的特定缺陷。然而,對於一個龐大且分散的用戶群體而言,修補程式的推送時程與全球部署狀態是降低風險的關鍵因素,因為在所有用戶間強制更新始終是一項持續的挑戰。
對 IT 團隊而言,此事件凸顯了數項立即優先事項。首先,必須確保所有微信用戶端——無論是企業設備還是用於工作的個人設備——都已更新至最新版本。其次,組織應審視微信在官方工作流程中的角色,並考慮是否需要為敏感討論採用替代的、更安全的通訊渠道。最後,流動設備管理(MDM)方案的使用變得更加重要,以強制執行應用程式更新,並可能控制企業網絡上允許使用哪些通訊應用程式。
儘管研究人員未觀察到大規模的現實世界攻擊,但針對微信這樣龐大用戶群平台的功能性、可自我傳播蠕蟲的公開示範,為惡意行為者提供了清晰的藍圖。此事件超越了單純的軟件缺陷,展示了一種針對無處不在的通訊應用程式、可擴展的攻擊模式,模糊了個人與企業安全之間的界線。
