{"slug": "wechat-s-1-4-billion-users-faced-a-dangerous-security-flaw-ai-helped-turn-it-a", "title": "WeChat's 1.4 Billion Users Faced a Dangerous Security Flaw. AI Helped Turn It Into a Self-Spreading Worm.", "summary": "Cybersecurity firm Calif demonstrated WeWorm, the first known zero-click worm that can spread through WeChat calls on both Apple's iOS and Google's Android, exploiting a flaw in WeChat's voice-calling system. Built in about a week with help from AI models, the worm could take over a WeChat account without user interaction and spread via saved contacts, potentially affecting hundreds of millions of the platform's 1.4 billion monthly active users. Tencent confirmed the flaw and said it fixed the issue by August 28, with no evidence of real-world exploitation.", "body_md": "# WeChat’s 1.4 Billion Users Faced a Dangerous Security Flaw. AI Helped Turn It Into a Self-Spreading Worm.\n\n## Palo Alto cybersecurity company Calif described WeWorm as the first known zero-click worm that can spread through WeChat calls on both Apple's iOS and Google's Android.\n\n[Artificial intelligence](https://www.ibtimes.com/topic/ai) created a worm inside WeChat so that a missed call could have been enough to surrender control of a WeChat account to a hacker. The contact would not have made the call, and the victim would not have needed to answer.\n\nOnce inside, the malicious software could use the account's saved contacts to repeat the attack, turning a familiar phone number into the next delivery system. That is the scenario researchers at Calif, a Palo Alto [cybersecurity](https://www.ibtimes.com/topic/cybersecurity) company, [demonstrated](https://calif.io/research/weworm) with a computer worm they named WeWorm.\n\nThe team built the tool in a little more than a week with help from advanced artificial intelligence models, exposing a vulnerability in one of the world's largest messaging platforms.\n\nTencent, which owns WeChat, confirmed the flaw and said it had fixed the issue after Calif contacted the company. A spokeswoman said Tencent had no reason to believe any users were affected or that security had been compromised. Customers do not need to update the app, the company said.\n\nAccording to Calif's research, the worm exploited a flaw in WeChat's voice-calling system. The researchers demonstrated the attack using an Android device that initiated a call to an iPhone, took over its WeChat account while the phone was ringing, and then used that compromised account to attack another Android device.\n\nThe victim did not have to answer, click a link, or interact with the phone. Once compromised, an account could be used to read and send messages, make calls, and impersonate its owner. Calif said additional vulnerabilities could potentially allow an attacker to gain full control of the device itself.\n\nWeChat grants certain privileges to people already saved as friends, and the worm could exploit that relationship to move from one account to another. A compromised contact could therefore become the gateway to everyone in that person's address book.\n\nCalif described WeWorm as the first known zero-click worm capable of spreading through WeChat calls across both [Apple](https://www.ibtimes.com/topic/apple)'s iOS and [Google](https://www.ibtimes.com/topic/google)'s Android. The company said it used a combination of open-source and leading U.S. AI models, but did not identify them.\n\nThe distinction between the researchers' demonstration and an actual outbreak is important. The worm was a proof of concept, and there is no evidence that millions of WeChat users were hacked. Vinh Nguyen, a former National Security Agency chief data scientist, [told The New York Times](https://www.nytimes.com/2026/09/08/us/politics/calif-ai-worm-wechat-hack.html) that the worm's ability to spread exponentially could have allowed it to reach hundreds of millions of devices within hours.\n\nWeChat has more than 1.4 billion monthly active users, according to the company, making the scale of the hypothetical threat extraordinary. Calif reported the flaw to Tencent in July and said it had mitigated the exploit for all users by August 28.\n\nCalif said its team discovered the bug and developed the first remote-code-execution exploit in about two days, then spent another week building the worm. The models accelerated the work, but researchers selected targets, supervised the process and tested the results. The disclosure follows an [open letter](https://openai.com/collective-cyberdefense/) signed by more than 100 technology companies, including OpenAI, warning that AI-enabled cyberattacks could become more widespread and sophisticated.\n\n© Copyright IBTimes 2026. All rights reserved.", "url": "https://wpnews.pro/news/wechat-s-1-4-billion-users-faced-a-dangerous-security-flaw-ai-helped-turn-it-a", "canonical_source": "https://www.ibtimes.com/wechats-14-billion-users-faced-dangerous-security-flaw-ai-helped-turn-it-self-spreading-worm-3807225", "published_at": "2026-09-08 17:48:34+00:00", "updated_at": "2026-09-08 18:19:14.325633+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-research"], "entities": ["Calif", "WeChat", "Tencent", "Apple", "Google", "Vinh Nguyen", "National Security Agency", "OpenAI"], "alternates": {"html": "https://wpnews.pro/news/wechat-s-1-4-billion-users-faced-a-dangerous-security-flaw-ai-helped-turn-it-a", "markdown": "https://wpnews.pro/news/wechat-s-1-4-billion-users-faced-a-dangerous-security-flaw-ai-helped-turn-it-a.md", "text": "https://wpnews.pro/news/wechat-s-1-4-billion-users-faced-a-dangerous-security-flaw-ai-helped-turn-it-a.txt", "jsonld": "https://wpnews.pro/news/wechat-s-1-4-billion-users-faced-a-dangerous-security-flaw-ai-helped-turn-it-a.jsonld"}}