LSN News › Vietnam

Politics · Vietnam Bureau

Security researchers discover WeChat vulnerability allowing account hijacking via missed calls

A California-based cybersecurity firm has identified a critical flaw in WeChat that could allow attackers to compromise user accounts through a single unanswered call. The vulnerability, which has since been patched, potentially exposed over one billion users to account takeover attacks.

LSN Vietnam · 12 September 2026

Security researchers discover WeChat vulnerability allowing account hijacking via missed calls

Researchers at the California security firm developed an artificial intelligence-powered tool that successfully demonstrated how WeChat accounts could be hijacked by exploiting a vulnerability triggered through missed calls. The discovery highlighted a significant security gap in the messaging platform, which serves as the primary communication and payment application for more than a billion users across China and globally.

The vulnerability functioned by leveraging the mechanics of incoming call notifications on the platform. By triggering a missed call through WeChat's system, attackers could potentially gain unauthorized access to user accounts without requiring any interaction from the target. The technique combined automated processes with machine learning capabilities to execute the account takeover.

Following responsible disclosure protocols, the security researchers notified WeChat's parent company Tencent of the vulnerability before making their findings public. Tencent has since implemented a fix to address the flaw, patching the affected systems to prevent further exploitation.

The incident underscores ongoing security challenges facing major technology platforms operating in Asia's digital ecosystem. WeChat's dual role as both a communication tool and financial payment system makes account security particularly critical, given the sensitive personal and financial information stored within user profiles.