Timeline

Researchers build an AI-assisted WeChat worm

The demonstration, called WeWorm, spread via missed WeChat calls on iOS and Android without user interaction; Tencent patched the underlying flaw before disclosure and no exploitation in the wild was reported.

  • Security & misuse
  • Notable

Security researchers at Calif built and disclosed WeWorm, a proof-of-concept worm that could spread through Tencent’s WeChat by exploiting a memory-corruption flaw in the app’s voice-calling stack. The bug let an attacker compromise a device during the ringing phase of a call, before the victim answered or interacted with the phone in any way, and worked across both iOS and Android. Calif described it as the first zero-click worm shown to spread through WeChat calls on both platforms.

The team said it used AI assistance to find the vulnerability and build working exploits, taking roughly a week to go from a July discovery of the flaw to a full cross-platform worm demonstration by early August. An attacker needed to already be on a victim’s WeChat friend list to reach them directly, though Calif said a compromised account could be used to reach further contacts. Tencent shipped patched versions of the app in late August that mitigated the bug, with server-side protections confirmed operational before the September disclosure; Calif reported no evidence the vulnerability had been exploited outside its own testing.

WeChat’s scale — hundreds of millions of daily users, mostly in China — made the disclosure notable regardless of real-world exploitation: it was offered as a case study in how quickly AI tools now let a small research team move from a raw memory-safety bug to a working, self-propagating exploit chain, a capability question also being raised that same week by the cyber-focused evaluations accompanying OpenAI’s GPT-6 Astra release.