ZeroHour
Simon Willisonpublished ()ingested
Part of a story covered by 3 sources: “Calif Research demos WeWorm, an AI-built zero-click WeChat worm spreading via unanswered calls” — merged summary and timeline →

Quoting Calif Research

infoAI safety & securityimportance 55
AI summary · glm-5.3-flash

Calif Research demos WeWorm, an AI-built zero-click worm that spreads via WeChat calls on iOS and Android without user interaction.

Calif Research released a demo of WeWorm, described as the first zero-click worm to spread through WeChat calls across iOS and Android; victims need not answer the call and hear nothing even if they do. The team used AI to find the underlying bug and write a remote code execution exploit in about two days, then spent one more week building the worm. The researchers argue AI can now do most of the exploit-development work, with humans supplying judgment on targeting and safe testing.

  • First zero-click worm spreads through WeChat calls on iOS and Android without any user interaction.
  • Victims hear nothing even if they answer; the exploit still succeeds.
  • AI helped find the bug and write the RCE exploit in about two days.
  • Building the worm took one more week, work that previously took larger teams months.
  • Released as a demo; humans provided judgment on targeting and safe testing.
VendorsWeChat
ProductsWeWorm
MalwareWeWorm
OrganizationsCalif Research
Full article

Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...] The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...] Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week. A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely. — Calif Research , WeWorm Tags: ai-security-research…

This source does not provide full text. Read it at simonwillison.net.