ZeroHour
Story · 1 source · 1 articlefirst updated ()2· 1 read

WeWorm: AI-built zero-click worm spreads through WeChat calls on iOS and Android; Tencent patched it in August

highExploit / PoCimportance 82
What's new: Added Simon Willison (2026-09-10) reporting on Calif's demo with three new details: victims hear nothing even if they answer the call and the exploit still succeeds; building the worm took one additional week after the two-day exploit, work the team says previously took larger teams months; and Calif's argument that AI can now do most exploit-development work while humans provide judgment on…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Security firm Calif used AI to build WeWorm, described as the first zero-click worm spreading through WeChat calls on iOS and Android: a memory-corruption flaw in WeChat's VoIP stack gives full account takeover via a crafted incoming call, even unanswered.…

Security firm Calif built WeWorm, which it describes as the first zero-click worm to spread through WeChat calls on iOS and Android. It exploits a memory-corruption flaw in WeChat's VoIP stack: a crafted incoming call triggers remote code execution within seconds with no user interaction, compromising the device while the call is still ringing; per Calif's demo, victims hear nothing even if they answer, and the exploit still succeeds. Sources differ on declining: Help Net Security reported exploitation may not occur if the call is declined within seconds, while Security Affairs and The Register reported that declining blocks that attempt (attackers can simply retry later). The compromise grants full control of the WeChat account, including reading and sending messages and making calls. The attacker must already be on the victim's friend list, but compromising a friend's account bypasses this, making each victim's contacts the propagation layer; in the demo the worm chained across three Android and iOS test phones - a Pixel 10a to an iPhone 17e to a second Pixel 10a - with each infected during the ringing call. Help Net Security projected the worm could reach millions of devices within hours. Calif said chaining the VoIP bug with other Android/iOS flaws could yield full smartphone control (The Register cited OEMpocalypse techniques); these chained-device scenarios remain hypothetical. WeChat and Weixin reported 1.418 billion combined monthly active users at the end of 2025 (Security Affairs; other outlets cited 1.4 billion-plus or over a billion, overwhelmingly in China). Calif found the flaw in July 2026 with LLM-assisted analysis (open-weight and frontier models), built its first RCE exploit in about two days, spent one more week building the worm, and reported the bug to Tencent in July 2026. Tencent confirmed it, shipped fixes in WeChat Android 8.0.77 and iOS 8.0.76 in August (The Register dates this to August 21), and applied server-side mitigations; no user action is required. Researchers found no evidence of real-world exploitation; testing used test phones. No CVE ID was disclosed, and full technical details are withheld for an upcoming conference presentation.

  • WeWorm is a proof-of-concept zero-click worm built by security firm Calif, described as the first to spread through WeChat calls across iOS and Android.
  • It exploits a memory-corruption flaw in WeChat's VoIP stack; a crafted incoming call yields remote code execution within seconds with no user interaction.
  • Zero-click exploitation succeeds while the call is still ringing; per Calif's demo, victims hear nothing even if they answer, and the exploit still succeeds.
  • Decline behavior differs by source: Help Net Security said exploitation may not occur if the call is declined within seconds; Security Affairs and The Register said declining blocks that attempt, though attackers can simply retry later.
  • The compromise grants full WeChat account control: reading and sending messages, and making calls.
  • The attacker must already be on the victim's friend list; compromised contacts become the propagation layer.
  • Demo chain: Pixel 10a to iPhone 17e to a second Pixel 10a - three Android and iOS test phones compromised in seconds during ringing calls.
  • Help Net Security projected the worm could reach millions of devices within hours.

Coverage timeline

  1. · 8d ago
    Cyber Security News· 68
    WeWorm – First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android

    Researchers demonstrated WeWorm, a zero-click worm exploiting a memory-corruption flaw in WeChat's VoIP stack to spread via calls across iOS and Android.