- Sources: primary, discussion
- Summary: Calif.io describes a memory-corruption bug in the VoIP stack of WeChat that yields full account takeover through an incoming call, with no user interaction, on both iOS and Android, and states the exploit requires the attacker to be on the victim's friend list. Calif.io notes the barrier is low because each compromised account reaches the contacts of the next victim, and that declining the call stops that attempt while the attacker can retry. Calif.io reported the bug to Tencent on 2026-07-24, Tencent published WeChat Android 8.0.77 and iOS 8.0.76 on 2026-08-21, and Calif.io states server-side mitigation was confirmed for all users on 2026-08-28.
- Why it matters: The friend-list precondition bounds each hop rather than the spread, and the team reports two days from bug to first remote code execution exploit working with AI, plus one further week to build the worm.
- Follow-up: Track any confirmation of exploitation in the wild.
send feedback on this story