Skip to content
archiveexploit · 08 Sep 2026 · 13:40 UTC

“Zero-click” WeChat worm could hijack accounts and spread via a single call

last 60 dispatches · spectrum

Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of each user, and uses the saved contacts to propagate itself further, potentially reaching millions of devices within hours. …

Sources · 2

outlets reporting the same story — pick one to read

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected