Het verhaal
Calif Research published WeWorm (research post dated 8 Sep 2026; Simon Willison highlighted it 10 Sep): a demo worm that hijacks WeChat over VoIP calls on both iOS and Android with zero clicks — the victim need not answer; declining stops that attempt but the attacker can retry. Compromise yields full control of the WeChat account (messages, calls, acting as the victim) and can chain to further friends because the attacker must be on the contact list. Calif says working with AI they found the memory-corruption VoIP bug and wrote the first RCE in about two days, then built the cross-platform worm in about a week — work that previously took larger teams months. They reported to Tencent in July; server-side mitigations are in place for all users (Android 8.0.77 / iOS 8.0.76 among the client fixes). Technical bug details are withheld pending a conference talk. Framed as an example of AI accelerating both offense capability and responsible disclosure.