Researchers Demonstrate WeChat Worm Capable of Hijacking Accounts via Incoming Calls
AI-generated from multiple sources. Verify before acting on this reporting.
SAN FRANCISCO — Researchers at a California-based technology firm unveiled a new cyberattack vector on Monday capable of hijacking WeChat user accounts through incoming calls, bypassing the need for victims to answer or interact with their devices. The demonstration, released globally on Sept. 8, 2026, highlights a critical vulnerability in the messaging platform's call-handling infrastructure that allows malicious code to execute remotely.
The newly identified worm exploits a flaw in how WeChat processes incoming voice and video call requests. Security experts demonstrated that simply placing a call to a target device is sufficient to trigger the payload, granting attackers full control over the compromised account without any user interaction. Once activated, the malware can access private messages, contacts, and financial data stored within the application, effectively turning the victim's phone into a tool for further espionage or fraud.
The researchers stated that the primary objective of releasing the exploit details was to raise urgent awareness regarding the intersection of artificial intelligence and telecommunications security. By showcasing the ease with which AI-driven attacks can manipulate existing communication protocols, the team aims to pressure governments and major technology companies to collaborate on new defensive frameworks. The demonstration serves as a stark warning that current security measures may be insufficient against automated threats capable of evolving in real-time.
WeChat, owned by Tencent, is used by over a billion people worldwide for messaging, social media, and mobile payments. The potential impact of such a vulnerability extends beyond individual privacy breaches to include the risk of large-scale financial theft and corporate espionage. While the researchers have not disclosed the specific technical mechanics of the exploit to prevent immediate misuse, they emphasized that the flaw exists in versions of the app currently deployed across multiple operating systems.
Tencent has not yet issued a public statement regarding the specific vulnerability or confirmed whether a patch is in development. The technology firm behind the demonstration urged users to remain vigilant and suggested that temporary measures, such as disabling incoming call notifications, might offer limited protection until a formal fix is distributed.
The incident raises broader questions about the security of global communication infrastructure as AI capabilities advance. Security analysts are now investigating whether similar vulnerabilities exist in other major messaging applications or if this flaw is unique to WeChat's architecture. As governments and tech giants assess the threat, the cybersecurity community awaits confirmation on whether the researchers will release a proof-of-concept tool to assist developers in patching the system.
The situation remains fluid as authorities determine the scope of potential exposure among global users. Until a definitive solution is implemented, millions of WeChat accounts may remain susceptible to unauthorized access through simple incoming calls.