Summary
Security researchers from Calif have discovered a zero-click WeChat VoIP flaw, dubbed "WeWorm," that allows account takeover on iPhone and Android devices simply by receiving a call, even if not answered. Tencent has since patched the vulnerability in Android 8.0.77 and iOS 8.0.76, with no evidence of in-the-wild exploitation.