Published September 15, 2026 - Mountain View, CA. Researchers disclosed a WeChat zero-click worm on September 9, 2026 that hijacks phones via incoming calls. The exploit chains two vulnerabilities to achieve remote code execution without user interaction. WeChat has patched the vulnerabilities in version 8.0.62.
Data last verified September 15, 2026 from Project Zero disclosure, Tencent security advisory, WeChat release notes, and Citizen Lab mobile exploit research.
Quick Answer
Researchers disclosed a WeChat zero-click worm on September 9, 2026 that hijacks phones via incoming calls. Two-vulnerability chain enables RCE without user interaction. WeChat 8.0.62 patches. Self-propagating capability. Last verified: Sep 15, 2026.
At a glance
- Disclosure date: September 9, 2026
- Affected versions: WeChat 8.0.58 and earlier (iOS + Android)
- Patched version: WeChat 8.0.62 (September 12, 2026)
- Attack vector: incoming call (zero-click)
- Exploitation chain: two vulnerabilities
- Self-propagating: yes, calls target's contacts
- Recommended action: update WeChat to 8.0.62
How the zero-click worm works
The WeChat zero-click worm chains two vulnerabilities to achieve remote code execution without user interaction. The malicious payload is delivered and executed before the phone rings.
The first vulnerability is in the WeChat call invitation handler. When an incoming call arrives, WeChat processes caller metadata to display the call screen. A specially crafted caller data payload exploits a parsing vulnerability that allows attacker-controlled data to be processed. The second vulnerability is in the audio processing pipeline. When the malicious caller data is processed, a memory corruption vulnerability allows arbitrary code execution. The two vulnerabilities combined enable remote code execution without any user interaction (Project Zero research disclosure, September 9, 2026; Tencent security advisory, September 2026).
Self-propagation capability
The worm propagates by calling the target's WeChat contacts. This makes it the first publicly disclosed zero-click mobile exploit with self-propagation.
Once a phone is compromised, the worm accesses the WeChat contacts list and calls each contact, delivering the same malicious payload. Because the worm spreads through normal WeChat call flow, the contacts see an incoming call from a known contact, which significantly increases the success rate compared to calls from unknown numbers. The worm could theoretically spread to thousands of contacts in hours if deployed at scale (Project Zero disclosure, September 9, 2026; Citizen Lab mobile worm analysis, 2026).
Affected versions and patch timeline
WeChat versions 8.0.58 and earlier are affected on both iOS and Android. The patch was released within 3 days of disclosure.
| WeChat version | Platform | Status | Action |
|---|---|---|---|
| 8.0.58 and earlier | iOS | Affected | Update to 8.0.62 |
| 8.0.58 and earlier | Android | Affected | Update to 8.0.62 |
| 8.0.59 to 8.0.61 | iOS + Android | Affected | Update to 8.0.62 |
| 8.0.62 | iOS + Android | Patched | No action |
Source: Tencent security advisory, September 2026; WeChat release notes, September 2026.
Protection steps for WeChat users
Five actions protect WeChat users from this and similar mobile messaging exploits. The most important is updating to 8.0.62.
| Action | Priority | Time required |
|---|---|---|
| Update WeChat to 8.0.62 or later | Critical | 5 minutes |
| Enable auto-update for WeChat in App Store / Google Play | High | 5 minutes |
| Don't accept calls from unknown contacts | Medium | Ongoing |
| Use WeChat on a separate device for sensitive communications | Medium | Configuration |
| Review connected devices list and remove unrecognized | Medium | 10 minutes |
Source: Tencent security advisory mitigation section, September 2026; Citizen Lab mobile security guidance, 2026.
Comparison to other mobile messaging exploits
Zero-click mobile messaging exploits have been disclosed for several platforms, but the WeChat worm's self-propagation capability is unique. The patch speed (3 days) was faster than typical.
| Platform | Year | Vulnerability | Self-propagating? | Patch time |
|---|---|---|---|---|
| 2019 | Pegasus (NSO Group) | No | 10 days | |
| iMessage | 2023 | FORCEDENTRY (Citizen Lab) | No | 15 days |
| Signal | 2024 | Limited video call vulnerability | No | 7 days |
| Telegram | 2024 | Memory corruption in call handler | No | 5 days |
| 2026 | Two-vuln zero-click worm | Yes | 3 days |
Source: Citizen Lab mobile exploit comparison, 2026; Project Zero disclosure timeline, September 2026.
Why the WeChat worm is particularly concerning
The combination of zero-click exploitation and self-propagation makes the WeChat worm uniquely dangerous among publicly disclosed mobile messaging exploits. Previous exploits required either user interaction or sophisticated delivery mechanisms.
Previous mobile messaging exploits (FORCEDENTRY on iMessage, Pegasus on WhatsApp) required sophisticated delivery infrastructure and typically targeted specific high-value individuals (journalists, dissidents, politicians). The WeChat worm's self-propagation capability means that a single successful deployment could spread to thousands of devices through normal WeChat calls. Even if the original attack vector requires some sophistication, the worm's ability to chain contacts makes it a true mass-exploitation tool. The 3-day patch window was fast but the disclosure itself may inspire copycat attacks on other mobile messaging platforms (Citizen Lab analysis, September 2026; Project Zero worm implications, September 2026).
FAQs
The questions above cover what the WeChat zero-click worm research is, how the worm works, which versions are affected, whether it's being exploited in the wild, how to protect your account, and how it compares to other mobile messaging exploits.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read moreShow less
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









