
WeChat zero-click call worm patched server-side after Calif demo spread across three test devices
Calif demonstrated a contact-only zero-click worm in WeChat that spread via incoming calls across iOS and Android test devices. Tencent applied an opaque server-side block in August 2026 without CVE or advisory. The case reveals persistent transparency gaps in high-volume Chinese messaging platforms and the speed of AI-assisted mobile exploit development.
The episode underscores how contact-graph apps concentrate risk: once one node is owned the trust model accelerates spread. AI-assisted discovery compressed the initial exploit to two days, suggesting similar low-friction paths exist in other messaging stacks. Next disclosure window is likely the conference where Calif plans to release technical details, potentially forcing broader platform response.
Tencent: No public CVE or technical advisory for the WeChat call flaw by 31 December 2026
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html)
- [2]Supporting Source(https://www.whatsapp.com/security/advisories/2023)
- [3]Supporting Source(https://citizenlab.ca/2023/07/nso-whatsapp-zero-click)