Skip to main content
See every side of every news story

Zero-Click AI Worm Can Hack WeChat Accounts Via Calls

Florida, US

LIONEL BONAVENTURE/AFP via Getty Images/Getty

LIONEL BONAVENTURE/AFP via Getty Images/Getty

What Happened

Calif, a Palo Alto security firm, used AI to find an RCE flaw in WeChat's VoIP stack and built WeWorm, a zero‑click self‑spreading worm that could hijack accounts and spread via contacts. Calif notified Tencent; Tencent patched the flaw and said no users appeared compromised.

What Happened

Calif, a Palo Alto security firm, used AI to find an RCE flaw in WeChat's VoIP stack and built WeWorm, a zero‑click self‑spreading worm that could hijack accounts and spread via contacts. Calif notified Tencent; Tencent patched the flaw and said no users appeared compromised.

Where Sources Agree

  • arrows_inputZero-Click Attack Mechanism: Reporting largely establishes that the WeWorm exploit enables a zero-click attack on Android and iOS devices by leveraging the VoIP stack to spread automatically through contact lists without requiring user interaction, according to Calif research.
  • arrows_inputVulnerability Mitigation Timeline: Outlets concur that Tencent addressed the WeChat vulnerability reported by Calif in July, mitigating the exploit for all users by August 28 with no evidence of compromise, according to official company statements.
  • arrows_inputWeChat User Base Scale: Most coverage notes that WeChat supports 1.4 billion monthly active users; this massive user base underscores the potential impact of security vulnerabilities, according to company data.

Where Sources Disagree

  • arrows_outputWeWorm Exploit Interaction Details: Reports vary slightly regarding user interaction with the WeWorm exploit; while some sources state no interaction is required, others note that declining the incoming call within seconds can prevent the exploit.
  • arrows_outputExtent of Human AI Supervision: While some reports highlight that human researchers selected targets, supervised the development process, and tested the results, the company emphasized that AI is already capable of performing most of the work required to build the exploit.

Timeline

September 8, 2026

Scale and policy implications highlighted: Reporting emphasized the potential scale of the threat — WeChat has more than 1.4 billion monthly users and experts warned the worm could have reached hundreds of millions of devices within hours — prompting Calif to urge using AI defensively and sparking broader discussions about AI-enabled cyberattacks and international cooperation. Calif published its research listing and public demonstration on September 8, 2026, to warn about AI-driven hacking risks.

September 8, 2026

Proof-of-concept worm demonstrated: Calif demonstrated a proof-of-concept worm called WeWorm that exploited a memory-corruption flaw in WeChat's VoIP stack to take over an account via a ringing call and then use that account to attack contacts — with no user interaction required. The researchers showed an Android device calling an iPhone, seizing the iPhone's WeChat account while it was ringing, and then propagating to another Android device.

August 28, 2026

Tencent patches and mitigates: After Calif reported the bug in July, Tencent issued app updates in August and later confirmed the exploit was mitigated on the server side for all users, saying it had fixed the flaw and saw no reason to believe users were affected. Calif also stated the exploit had been mitigated for all users by August 28.

Summaries by Ground AI

Sources

See All 36
View All Sources

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal