deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

Researchers demo WeWorm, a zero-click worm spreading through WeChat calls

Calif says its AI-assisted research produced a worm that hijacked WeChat accounts through incoming calls alone; Tencent shipped and enforced a fix for all users in August.

Researchers demo WeWorm, a zero-click worm spreading through WeChat calls

A worm that spreads by ringing your phone

Security firm Calif has published a demonstration of a self-propagating worm, which it calls WeWorm, that spreads through WeChat voice calls on both iOS and Android without the person on the receiving end touching their phone. The company describes it as the first worm shown to spread this way through WeChat, and presents it as the opening entry in a research series on zero-click attack surfaces in mobile messaging apps.

A three-phone demonstration

Calif's proof of concept chained three handsets together. A Pixel 10a running Android played the attacker and placed a call to an iPhone 17e. According to Calif, the exploit fired while the iPhone was still ringing and seized control of its WeChat account. The compromised iPhone then called a second Pixel 10a and took it over the same way, converting each victim into the next attacker.

The firm says the takeover takes seconds and grants full control of the WeChat account, including the ability to read and send messages, place calls and otherwise act as the victim. Calif adds that when chained with other Android and iOS bugs it has previously reported and is helping to fix, the flaw could be escalated to full control of the device itself.

No click, no answer, no sound

The defining property of the attack is that the target never has to interact with the phone. The exploit runs while the call is ringing. If the victim answers, they hear nothing and the attack still succeeds, Calif says. Declining the call blocks that particular attempt, but an attacker can simply redial later, for example while the target is asleep.

There is one precondition: the caller must be on the victim's friend list. Calif argues this is a weak defence, because messaging apps grant trusted contacts extra privileges, so compromising a single contact lets an attacker inherit that trust and reach everyone the contact knows.

The bug and the fix

Calif identifies the underlying flaw as a memory corruption issue in WeChat's VoIP stack and is withholding technical details until it presents a full analysis at an upcoming conference.

The disclosure timeline published by the firm runs as follows: its AI systems found the bug at some point in July 2026, the engineering team learned of it on 23 July, and it was reported to Tencent on 24 July. Calif's own WeChat accounts were banned from 25 to 28 July and restored on 29 July. The first Android remote code execution exploit was finished on 30 July, the iOS equivalent on 2 August, and the polished worm demo on 11 August. Tencent shipped mitigations in WeChat 8.0.77 for Android and 8.0.76 for iOS on 21 August, and Calif confirmed on 28 August that its exploit had been neutralised on the server side for all users. On 4 September Tencent verified that the bug could indeed be exploited for remote command execution, and Calif published its findings on 8 September, alongside coverage in The New York Times.

Built with AI in days, not months

The firm's most striking claim concerns speed. Working with AI, Calif says it found the bug and wrote the first remote code execution exploit in roughly two days, with the finished worm taking another week, work that previously would have required a larger team months to complete.

Calif frames this as a warning: these capabilities have existed for a long time in the hands of well-funded attackers, but AI is now making them reachable for less skilled actors, sharply raising the risk to ordinary users. The researchers point to WannaCry, which escaped from tooling that leaked early and disrupted hospitals, as an example of what an accidentally released half-finished worm could do at WeChat's scale.

Their stated conclusion, however, is not to slow AI development. The vulnerabilities already exist, Calif argues, and the same tooling lets defenders find and fix them faster. The firm closes with a call for the United States, China and other governments to collaborate with private industry on using AI to improve security.

Why it matters

WeChat is used by nearly everyone in China and by Chinese communities worldwide, and Calif estimates that a worm of this kind could have compromised more than a billion accounts. The demonstration shows that zero-click propagation is practical on the world's largest messaging platform, and that the VoIP surfaces handling incoming calls are part of the attack surface users never chose to expose. It also shows AI compressing exploit development from months into days, which changes the calculus for attackers and defenders alike. Users are protected only if they run current WeChat versions, and Calif says similar unconventional attack surfaces exist across many other messaging apps, meaning broader fixes may require action from platform owners as well as app developers.

  • #security
  • #wechat
  • #zero-click
  • #mobile
  • #vulnerabilities

Related posts