cd /news/ai-safety/weworm-zero-click-worm-could-have-ta… · home topics ai-safety article
[ARTICLE · art-132055] src=heise.de ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

"WeWorm": Zero-click worm could have taken over all WeChat accounts

Security company Calif reported that it used an AI system to discover a zero-click WeChat vulnerability, dubbed "WeWorm," that could have spread between accounts via unanswered VoIP calls and taken over more than a billion smartphones or accounts on both Android and iOS. Calif reported the bug to Tencent on July 24, and Tencent patched it on August 21; Calif said the AI-assisted exploit took two days to develop and the worm another week, versus months for a larger human team. The flaw stemmed from WeChat's VoIP technology granting stored contacts elevated rights, letting calls appear to come from a known contact and infect devices whether or not the call was answered.

by read2 min views2 publishedSep 16, 2026
"WeWorm": Zero-click worm could have taken over all WeChat accounts
Image: source

An AI found a vulnerability in WeChat that could have been used to take over a billion accounts in a very short time. It has since been closed.

The California-based security company Calif has, according to its statements, developed a worm using AI technology that could spread from one WeChat account to another via a simple call and take them all over. Those responsible calculate, based on WeChat’s usage numbers, that exploiting the technique, dubbed “WeWorm,” could have taken over more than a billion smartphones or accounts. The takeover reportedly occurred during the call, which did not need to be answered. This worked on both Android and iOS. In July, Calif reported the underlying bug to Tencent, and after some back and forth, the Chinese company closed the vulnerability with updates. This means all users are now safe.

Rapid spread realistically unstoppable

According to Calif, WeWorm was the first worm that could spread across Android and iOS devices without user interaction (“Zero-Click”). While the infection could have been prevented by rejecting the call within seconds, the call could have been repeated at a later time. The attack method was based on a vulnerability in WeChat’s VoIP technology, which gives stored contacts – as is common elsewhere – more rights. The worm would therefore have spread between contacts, and the calls would have apparently come from a known contact. The infection occurred regardless of whether the call was answered or ignored.

The vulnerability was originally found by an AI system at Calif, according to the blog post. Previously, a larger team would have taken months to search for and develop the worm; with AI support, it took two days for the exploit and another week for the worm. Nevertheless, Calif believes it is wrong to “blame AI and hinder its further development.” The vulnerabilities exist; “what AI has changed is that we can find them and close them quickly.” Assuming there are more good people than bad, the good guys could win the day.

Videos by heise

According to the chronology, the vulnerability was discovered in July. On July 24, it was reported to Tencent, after which Calif’s WeChat accounts were initially blocked. This was then reversed, and the patches followed on August 21. By then, accounts on the all-encompassing app could have been taken over via the worm itself. Further vulnerabilities would have been necessary for a complete takeover of the respective smartphone. However, Calif itself presented a technique just a few days ago under the designation OEMpocalypse, which allows administrative access (“root”) on Android devices from various manufacturers via an application without special rights. In the wrong hands, WeWorm could therefore have caused enormous damage.

(mho)

── more in #ai-safety 4 stories · sorted by recency
blog.calif.io · · #ai-safety
WeWorm
── more on @calif 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/weworm-zero-click-wo…] indexed:0 read:2min 2026-09-16 ·