{"slug": "weworm-zero-click-worm-could-have-taken-over-all-wechat-accounts", "title": "\"WeWorm\": Zero-click worm could have taken over all WeChat accounts", "summary": "Security company Calif reported that it used an AI system to discover a zero-click WeChat vulnerability, dubbed \"WeWorm,\" that could have spread between accounts via unanswered VoIP calls and taken over more than a billion smartphones or accounts on both Android and iOS. Calif reported the bug to Tencent on July 24, and Tencent patched it on August 21; Calif said the AI-assisted exploit took two days to develop and the worm another week, versus months for a larger human team. The flaw stemmed from WeChat's VoIP technology granting stored contacts elevated rights, letting calls appear to come from a known contact and infect devices whether or not the call was answered.", "body_md": "# \"WeWorm\": Zero-click worm could have taken over all WeChat accounts\n\nAn AI found a vulnerability in WeChat that could have been used to take over a billion accounts in a very short time. It has since been closed.\n\nThe California-based security company Calif has, according to its statements, developed a worm using AI technology that could spread from one WeChat account to another via a simple call and take them all over. Those responsible calculate, based on WeChat’s usage numbers, that exploiting the technique, dubbed “WeWorm,” could have taken over more than a billion smartphones or accounts. The takeover reportedly occurred during the call, which did not need to be answered. This worked on both Android and iOS. In July, Calif reported the underlying bug to Tencent, and after some back and forth, the Chinese company closed the vulnerability with updates. This means all users are now safe.\n\n### Rapid spread realistically unstoppable\n\nAccording to Calif, [WeWorm](https://calif.io/research/weworm) was the first worm that could spread across Android and iOS devices without user interaction (“Zero-Click”). While the infection could have been prevented by rejecting the call within seconds, the call could have been repeated at a later time. The attack method was based on a vulnerability in WeChat’s VoIP technology, which gives stored contacts – as is common elsewhere – more rights. The worm would therefore have spread between contacts, and the calls would have apparently come from a known contact. The infection occurred regardless of whether the call was answered or ignored.\n\nThe vulnerability was originally found by an AI system at Calif, according to the blog post. Previously, a larger team would have taken months to search for and develop the worm; with AI support, it took two days for the exploit and another week for the worm. Nevertheless, Calif believes it is wrong to “blame AI and hinder its further development.” The vulnerabilities exist; “what AI has changed is that we can find them and close them quickly.” Assuming there are more good people than bad, [the good guys could win the day](https://www.heise.de/news/271-Firefox-Luecken-dank-Mythos-KI-geschlossen-Durchbruch-fuer-IT-Sicherheit-11267401.html?from-en=1).\n\nVideos by heise\n\nAccording to the chronology, the vulnerability was discovered in July. On July 24, it was reported to Tencent, after which Calif’s WeChat accounts were initially blocked. This was then reversed, and the patches followed on August 21. By then, accounts on the all-encompassing app could have been taken over via the worm itself. Further vulnerabilities would have been necessary for a complete takeover of the respective smartphone. However, Calif itself presented a technique just a few days ago under the designation [OEMpocalypse](https://calif.io/research/oempocalypse), which allows administrative access (“root”) on Android devices from various manufacturers via an application without special rights. In the wrong hands, WeWorm could therefore have caused enormous damage.\n\n([mho](mailto:mho@heise.de))", "url": "https://wpnews.pro/news/weworm-zero-click-worm-could-have-taken-over-all-wechat-accounts", "canonical_source": "https://www.heise.de/en/news/WeWorm-Zero-click-worm-could-have-taken-over-all-WeChat-accounts-11445510.html", "published_at": "2026-09-16 23:14:43+00:00", "updated_at": "2026-09-16 23:24:00.041954+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-research"], "entities": ["Calif", "WeChat", "Tencent", "WeWorm", "Android", "iOS", "OEMpocalypse"], "alternates": {"html": "https://wpnews.pro/news/weworm-zero-click-worm-could-have-taken-over-all-wechat-accounts", "markdown": "https://wpnews.pro/news/weworm-zero-click-worm-could-have-taken-over-all-wechat-accounts.md", "text": "https://wpnews.pro/news/weworm-zero-click-worm-could-have-taken-over-all-wechat-accounts.txt", "jsonld": "https://wpnews.pro/news/weworm-zero-click-worm-could-have-taken-over-all-wechat-accounts.jsonld"}}