Story perspectives
AI-built WeWorm exploits WeChat VoIP flaw, auto-spreads
9/9/2026
1 of 1
Story summary
- California researchers built the self-spreading WeWorm worm using AI.
- WeWorm exploited a memory-corruption flaw in WeChat’s VoIP stack for zero-click code execution.
- Researchers reported the flaw to Tencent in July.
- Tencent released WeChat updates 8.0.76 (iOS) and 8.0.77 (Android) in August, adding server mitigations and seeing no active exploitation.
- The worm auto-called contacts, potentially reaching hundreds of millions of devices.
