Security researchers at Calif developed WeWorm, a zero-click worm that could compromise WeChat accounts through an incoming call that the recipient did not need to answer. Tencent has since blocked the underlying flaw and says it has found no evidence that users were targeted with it.

The attack exploited a memory-corruption issue in WeChat’s VoIP component. An attacker had to already be on a target’s friend list, but could trigger the compromise while the phone was ringing, without a link click or any other action from the victim. Once an account was compromised, its friend list could be used to continue the worm’s spread.

Calif demonstrated the propagation chain across three handsets:

  • A Pixel 10a initiated an attack against an iPhone 17e.
  • The compromised iPhone 17e account was used to attack a second Pixel 10a.
  • Researchers said they could take control of a WeChat account within seconds, allowing them to read and send messages and place calls.

That access did not amount to full control of the affected phone. Taking over an entire Android or iOS device would require chaining the WeChat exploit with additional platform vulnerabilities.

AI shortened the route from flaw to worm

According to Calif, the team used AI models to identify the issue and produce an initial remote-code-execution exploit in about two days. Building the cross-platform worm, capable of moving between iOS and Android, took roughly another week. The researchers said human operators selected targets, checked outputs and directed the work rather than leaving the process to AI alone.

The demonstration matters because Weixin and WeChat together have more than 1.4 billion monthly active users, according to Tencent. Vinh Nguyen, a former NSA chief data scientist, estimated to The New York Times that a worm of this kind could have reached hundreds of millions of devices within hours if released. That was a projected scenario, not an event that occurred.

Calif reported the issue to Tencent on July 24. WeChat 8.0.77 for Android and version 8.0.76 for iOS arrived on August 21, and the researchers confirmed on August 28 that Tencent had deployed a server-side block that stopped their exploit for all users. Tencent said the fix required no user action.

WeWorm did not become an active outbreak, but it illustrates how AI tools can reduce the time required to turn a newly found vulnerability into a functional zero-click attack. The key remaining concern is whether defenders can continue to identify and neutralize such chains before they reach users at scale.

SOURCEnytimes.com
Previous articleHuawei Adds 512GB MatePad Air 2026 Model and Lower-Cost Enjoy Edition in China
Next articleSamsung Galaxy Tab S12+ and Tab S12 Ultra tipped for October 7 debut