Return to Threats

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

thehackernews.com 2026-09-08 AI supply chain High

What Happened

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

Why It Matters

Report facts: Researchers at security firm Calif demonstrated a zero-click worm exploiting a vulnerability in WeChat that can take over accounts on both iPhone and Android via an incoming call, without user interaction, as long as the caller is an existing contact. They reported the flaw to Tencent in July, and Tencent has since responded to the issue. RealGround analysis: Although this incident targets mobile app security rather than an AI model directly, it highlights supply-chain exposure where widely deployed, AI-enabled platforms like super apps become high-value targets and any integrated AI services could be indirectly compromised. Organizations relying on third-party messaging or super-app ecosystems for AI agents should treat such client vulnerabilities as part of their AI supply chain risk, reviewing SBOMs, hardening integrations, and conducting readiness assessments for cascading account-takeover scenarios.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html

Talk to AI CISO