← Overzicht

Calif WeWorm: AI-sped zero-click WeChat call worm (iOS + Android)

· opgehaald 18:09

Calif Research demo’d WeWorm — a zero-click worm that spreads via WeChat VoIP calls across iOS and Android without the victim answering. With AI they found the bug and wrote the first RCE in ~2 days; the worm in another week. Tencent has mitigated; NYT covered the drop.

Calif Research published WeWorm (research post dated 8 Sep 2026; Simon Willison highlighted it 10 Sep): a demo worm that hijacks WeChat over VoIP calls on both iOS and Android with zero clicks — the victim need not answer; declining stops that attempt but the attacker can retry. Compromise yields full control of the WeChat account (messages, calls, acting as the victim) and can chain to further friends because the attacker must be on the contact list. Calif says working with AI they found the memory-corruption VoIP bug and wrote the first RCE in about two days, then built the cross-platform worm in about a week — work that previously took larger teams months. They reported to Tencent in July; server-side mitigations are in place for all users (Android 8.0.77 / iOS 8.0.76 among the client fixes). Technical bug details are withheld pending a conference talk. Framed as an example of AI accelerating both offense capability and responsible disclosure.