WeChat Flaw Allows Account Takeover Through Incoming Calls

A security flaw in WeChat lets hackers take over accounts with just a call from a contact. Users don't need to answer or interact.

ThreatVectr Newsdesk· 2 min read
Photoreal news-editorial image, full-frame 16:9, edge to edge
Share

Key points

  • Calif researchers discovered a WeChat flaw in July 2023.
  • The vulnerability allows account takeover via an incoming call.
  • Tencent was notified and is working on a patch.

How does this vulnerability work?

Researchers from Calif, a security firm, found a way to take control of a WeChat account merely through an incoming call. The call must be made by someone already in the user's WeChat contacts, but there's no need for the user to answer or interact with their phone. The researchers demonstrated this flaw by spreading it among three test phones.

WeChat, a popular messaging app, is used by millions worldwide. A flaw like this raises serious concerns about user privacy and security. Calif reported the issue to Tencent, WeChat's parent company, in July 2023. Tencent is now working on a fix for this vulnerability.

Should users be worried?

Users should be cautious but not panic. The vulnerability only allows someone already in your contacts to exploit it, reducing the risk of random attacks. However, it's a reminder of the importance of regularly checking app permissions and being cautious about who you add to your contact list.

What should WeChat users do?

While Tencent develops a patch, users should ensure their app is up-to-date and review their contact list, removing any unknown or suspicious contacts.

This incident was first reported by The Hacker News. It highlights the need for strong security practices in app development and user awareness.

© 2026 Threat Vectr