# Quoting Calif Research

> Source: <https://simonwillison.net/2026/Sep/10/calif-research/>
> Published: 2026-09-10 00:56:41+00:00

Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...]

The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...]

Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week.

A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely.

— [Calif Research](https://calif.io/research/weworm), WeWorm

Tags: [ai-security-research](https://simonwillison.net/tags/ai-security-research), [ai](https://simonwillison.net/tags/ai), [llms](https://simonwillison.net/tags/llms), [security](https://simonwillison.net/tags/security), [generative-ai](https://simonwillison.net/tags/generative-ai)
