September 30, 2026

WeChat-WeWorm Zero-Click Exploit

high-severity security vulnerability

Lookout Coverage and Recommendation for Admins

Lookout is scheduled to release security coverage for the WeWorm exploit on October 1, 2026. Coverage was prioritized based on the critical zero-click nature and automated propagation capability of the exploit across mobile endpoints. Once deployed, the platform will automatically generate alerts and initiate workflows in accordance with each administrator’s configured risk thresholds, response policies, and escalation procedures.

To ensure mobile endpoints are protected, Lookout administrators should take the following actions in the Lookout console:

  • Enable Application Vulnerability Policies: Configure vulnerability detection policies to identify devices running unpatched versions of WeChat for Android (below 8.0.77) and WeChat for iOS (below 8.0.76). Set policy severity to High and enforce conditional access policies to block access to corporate data until updates are applied.
  • Remediate Application Versions: Ensure the WeChat application is updated to patched builds across mobile endpoints via the Google Play Store, Apple App Store, or enterprise EMM/MDM portal.
  • Enable Lookout Phishing & Content Protection (PCP): Activate PCP across all enrolled endpoints to inspect network traffic and block known malicious command-and-control server domains or network vectors associated with WeWorm exploit traffic.

Overview 

Security firm Calif has disclosed a critical zero-click remote code execution vulnerability affecting WeChat. The exploit, named WeWorm, is a critical-severity memory corruption vulnerability in WeChat’s Voice-over-IP (VoIP) call-handling stack impacting both Android and iOS devices. No official CVE identifier has been assigned to this vulnerability.

This flaw stems from a memory corruption bug within WeChat's VoIP call-handling engine, allowing unauthenticated remote code execution. An attacker can exploit this vulnerability simply by placing an incoming WeChat VoIP call to a target account. The attack requires zero user interaction, triggering within seconds while the phone rings and regardless of whether the call is answered. Notably, the initial attacker must be on the victim's WeChat contact list; however, once an account is compromised, the worm uses saved contacts to automatically propagate peer-to-peer to additional devices. While initial execution gives the attacker full control of the WeChat account (reading/sending messages, placing calls, and account impersonation), chaining this flaw with additional OS-level vulnerabilities can escalate to full device takeover.

Devices running versions below these thresholds are vulnerable and should be updated immediately to eliminate client-side exposure. Enterprise organizations are strongly advised to enforce immediate remediation across all mobile endpoints to reduce risk. 

Lookout Analysis

This exploit poses a maximum risk to Confidentiality, Integrity, and Availability. Successful exploitation enables attackers to execute arbitrary code to access sensitive enterprise data—including chat history, authentication tokens, contact lists, and user PII—while facilitating unauthorized actions and peer-to-peer worm propagation within the context of the vulnerable application.

The exploitation of the WeWorm exploit follows these stages of the kill chain: 

  1. Remote Trigger: Attacker initiates an incoming WeChat VoIP call to a user on their contact list (no link or user interaction required).
  2. Parsing: The WeChat VoIP protocol parser processes the incoming connection while the device is ringing.
  3. Memory Corruption: The VoIP engine fails to handle incoming call-handling memory safely, leading to memory corruption and enabling attackers to execute arbitrary code.
  4. Code Execution: Attacker gains code execution within the WeChat process, compromising application memory, access tokens, and user credentials.
  5. Post-Exploitation: Attacker uses compromised credentials and saved contact lists to automatically place calls and spread the worm to additional contacts, or chains local OS vulnerabilities to achieve full device compromise.

Authors

Abstract fan-shaped digital art with green and yellow gradient bars radiating from the center.

Lookout

Endpoint Security
Icon of a white document with lines on a dark circular background.
Entry Type
Threat Guidances
Icon of a broken smartphone with a crack on the screen.
Threat Type
Vulnerability
Green Android robot mascot icon with antennas and eyes on a transparent background.
Platform(s) Affected
Android
Black icon of an upward arrow inside a 50x50 pixel square.
Platform(s) Affected
iOS
Computer screen showing a code editor with Python code implementing a dictionary filter function.
Platform(s) Affected
Threat Guidances
Vulnerability
Android
iOS
A woman using her phone and laptop on a train ride.Abstract white wavy lines creating a smooth flowing pattern on a light background.

Lookout Mobile Endpoint Security

Stop Cyberattacks Before They Start With Industry-Leading Threat Intelligence.

Advanced mobile Endpoint Detection & Response powered by data from 185M+ apps and 200M+ devices on iOS, Android, ChromeOS.

HeaderHeaderHeaderHeader
CellCellCellCell
CellCellCellCell
CellCellCellCell
CellCellCellCell