Quoting Calif Research Calif Research released a demo of WeWorm, which it calls the first zero-click worm to spread through WeChat calls on iOS and Android, requiring no action from the victim. Calif Research said its team, working with AI, found the bug and wrote the first remote code execution exploit in about two days, then built the worm in one more week — work that previously took a larger team months. The team said it supplied the judgment on what to target and how to test safely. Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. ... The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. ... Working with AI, our team found the bug and wrote the first remote code execution RCE exploit in about two days. Building the worm took one more week. A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely. — Calif Research https://calif.io/research/weworm , WeWorm Tags: ai-security-research https://simonwillison.net/tags/ai-security-research , ai https://simonwillison.net/tags/ai , llms https://simonwillison.net/tags/llms , security https://simonwillison.net/tags/security , generative-ai https://simonwillison.net/tags/generative-ai