Calif Research demos WeWorm, an AI-built zero-click WeChat worm spreading via unanswered calls
Researchers at Calif built WeWorm, described as the first zero-click worm spreading through WeChat calls on iOS and Android via a VoIP memory-corruption RCE; Tencent patched the flaw on August 21 in WeChat Android 8.0.77 and iOS 8.0.76, with no in-the-wild…
Security firm Calif Research demonstrated WeWorm, a worm exploiting a memory corruption vulnerability in WeChat's VoIP stack that yields remote code execution from a crafted incoming call with no user interaction. The flaw was found in July using LLM-assisted analysis (open-weight and frontier models), and the team built its first working RCE exploit in about two days, then spent roughly one more week assembling the worm — work the researchers say previously took larger teams months. A successful exploit grants full control of the victim's WeChat account, including reading and sending messages and making calls, and the worm self-propagates by calling the victim's contacts on iOS and Android. The attacker only needs to be on the victim's friend list, which is easily achieved by compromising a trusted contact first; Calif said chaining the bug with other Android and iOS flaws (e.g., OEMpocalypse techniques) could compromise entire devices. Tencent confirmed and patched the bug on August 21 in WeChat Android 8.0.77 and iOS 8.0.76. The demo was tested only on test phones, with no in-the-wild exploitation reported, and a full technical analysis is planned for an upcoming conference. One point of disagreement: The Register reports that declining the call prevented infection, while Infosecurity Magazine and Simon Willison state the exploit succeeds even if the victim never answers (and victims hear nothing even if they do).
- WeWorm is described as the first zero-click worm spreading through WeChat calls on iOS and Android.
- Root cause: memory corruption in WeChat's VoIP stack, discovered by Calif in July 2026 using open-weight and frontier LLM-assisted analysis.
- AI helped find the bug and write the first RCE exploit in about two days; building the worm took roughly one additional week.
- Tencent shipped patches on August 21, 2026, in WeChat Android 8.0.77 and iOS 8.0.76.
- Attacker must be on the victim's friend list; compromised accounts then target trusted contacts to self-propagate.
- Exploit grants full WeChat account control — reading and sending messages and making calls — reportedly within seconds.
- Chaining with other Android/iOS bugs, such as OEMpocalypse techniques, could yield full device control.
- WeChat has over 1.4 billion monthly active users, amplifying potential worm impact.
Coverage timelineoldest first · each row is one article
- · 6d agoWeChat worm could pwn a friend before they even answered the call
The Register · Security· 68
Calif researchers demoed WeWorm, a zero-click WeChat VoIP memory-corruption worm enabling account takeover; Tencent patched it August 21.
- · 6d agoResearchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
Infosecurity Magazine· 62
Calif researchers built WeWorm, a zero-click worm exploiting a WeChat VoIP memory-corruption RCE that Tencent has now patched.
- · 5d agoQuoting Calif Research
Simon Willison· 55
Calif Research demos WeWorm, an AI-built zero-click worm that spreads via WeChat calls on iOS and Android without user interaction.