Full Breakdown
AI-Built “WeWorm” Demonstrates Zero-Click Threat to WeChat
9/9/2026, 10:13:40 AM
The WeWorm Attack
Researchers at the Palo Alto-based cybersecurity firm Calif created a self-spreading computer worm, dubbed WeWorm, that can hijack WeChat accounts on both Android and iOS devices with a single incoming call. The exploit requires no user interaction; the malicious code executes while the phone is ringing, allowing the attacker to read messages, place outgoing calls, and fully control the compromised account. By automatically calling contacts saved in the victim’s address book, the worm can propagate rapidly, potentially reaching hundreds of millions of devices within hours.
Technical Details and AI Role
Calif’s team identified a memory-corruption flaw in WeChat’s VoIP stack and produced an initial remote-code-execution exploit in roughly 48 hours using a mix of commercial and open-source artificial-intelligence models. Building the full worm took an additional week. Demonstrations showed the worm moving from an Android phone to an iPhone and then to another Android device, all without the target answering the call. The attack succeeds even if the call is declined, though repeated attempts are required when the victim is unavailable.
Responses from Calif and Tencent
Thai Duong, chief executive of Calif, described the vulnerability as “exceptional” and warned that its simplicity would be “a dream come true” for malicious actors. Calif reported the flaw to Tencent, the owner of WeChat, in July. In August, Tencent released client updates—versions 8.0.76 for iOS and 8.0.77 for Android—and implemented server-side blocks to neutralize the exploit. Tencent has stated that it has observed no active exploitation of the worm in the wild.
Implications for Cybersecurity
The WeWorm proof-of-concept illustrates how AI tools can compress the timeline for developing functional zero-click exploits from months to days. With over 1.4 billion active WeChat users worldwide, the demonstration underscores the heightened risk posed by AI-accelerated vulnerability research, especially for platforms that serve as “super apps” integrating messaging, payments, and essential services. The episode highlights the need for rapid patch cycles and proactive security testing to mitigate threats that can spread without any user action.
