{"slug": "weworm", "title": "WeWorm", "summary": "Calif.io researchers published WeWorm, an exploit that compromises WeChat accounts via a single unanswered phone call, and reported it to Tencent, which has mitigated the vulnerability for all users. The team, using AI, wrote the first remote code execution exploit in about two days, highlighting the potential for AI to accelerate vulnerability discovery and the need for US-China cooperation on cybersecurity.", "body_md": "Today we published WeWorm. All it takes is one phone call. You don't have to answer. Within seconds, your WeChat account is compromised and can be used to call your friends and spread the attack further.\n\nWorking with AI, our team found the bug and wrote the first RCE exploit in about two days. We reported it to Tencent, and our exploit has now been mitigated for all users.\n\nWe hope this work sets an example. The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them.\n\nAI gives us an opportunity to find and fix vulnerabilities faster than ever, and we should work together to make the world safer for everyone.\n\nRead our story and watch the demos: [https://calif.io/research/weworm](https://calif.io/research/weworm).\n\nThe New York Times also spent time following our work and published their story today: [https://archive.is/arHsF](https://archive.is/arHsF)", "url": "https://wpnews.pro/news/weworm", "canonical_source": "https://blog.calif.io/p/weworm", "published_at": "2026-09-08 09:56:34+00:00", "updated_at": "2026-09-08 10:03:33.274392+00:00", "lang": "en", "topics": ["ai-research", "ai-safety", "ai-policy"], "entities": ["Calif.io", "Tencent", "WeChat", "WeWorm", "The New York Times"], "alternates": {"html": "https://wpnews.pro/news/weworm", "markdown": "https://wpnews.pro/news/weworm.md", "text": "https://wpnews.pro/news/weworm.txt", "jsonld": "https://wpnews.pro/news/weworm.jsonld"}}