WeChat WeWorm zero-click worm patched after AI find

Tencent has fixed a critical zero-click wormable flaw in WeChat that allowed security firm Calif to build “WeWorm,” a self-spreading exploit capable of hijacking accounts via voice-over-IP calls on both iOS and Android.[1][2][4] The episode shows how AI-accelerated vulnerability research can turn a single bug in a dominant messaging app into a planet-scale risk for more than 1.4 billion users.[1][3][8]

Calif describes the underlying issue as a memory corruption bug in WeChat’s VoIP stack that can be triggered remotely during an incoming call, giving an attacker full control of the victim’s account without any taps or swipes.[1][2][4] In demonstrations, the exploit took over an account within seconds even when the target did not answer, then used the compromised profile to automatically call another contact and repeat the process, creating a classic worm-like propagation chain.[1][2][3] The only reliable way to avoid infection in Calif’s tests was to actively decline the call; simply letting it ring or answering was enough for the worm to succeed, and any compromised account in a user’s friend list could be used to target additional trusted contacts.[2][3][4]

Calif reported the vulnerability to Tencent on 24 July 2026, and the company responded by shipping patched WeChat clients—Android 8.0.77 and iOS 8.0.76—on 21 August, followed by server-side mitigations confirmed by the researchers on 28 August.[2][5][8] Tencent has acknowledged the flaw and stated there is no evidence that WeWorm has been used in real-world attacks so far, a view echoed in multiple independent reports.[1][6][7] No CVE identifier has been published for the WeChat VoIP bug, and security write-ups note that this is a new issue, distinct from earlier VoIP-stack memory corruption flaws seen in other messaging platforms.[2][9][11]

Calif says it used AI models to discover the vulnerability and build its first remote code execution exploit within days, arguing that such tooling can give smaller teams capabilities once reserved for well-funded, state-backed actors.[1][6][15] Ryan Fedasiuk, an adjunct assistant professor in Georgetown University’s Security Studies Program, has called WeWorm “an extremely serious incident” and urged the United States and China to maintain open channels for sharing information as AI increases both the scale and speed of cyber threats.[8][15] Commentators have compared WeWorm’s zero-click call-based takeover to past VoIP exploits such as WhatsApp’s CVE-2019-3568 buffer overflow, underscoring that real-time communications stacks remain a high-value target for remote compromise.[9][11][14]

From a defender’s perspective, WeWorm is a reminder that messaging accounts can serve as stepping stones to full device compromise when chained with other iOS and Android vulnerabilities, even though Calif is withholding technical details of any complete attack chains until an upcoming conference talk.[2][4] Organizations should ensure managed devices are running at least WeChat 8.0.77 on Android or 8.0.76 on iOS and watch for unusual call patterns or sudden account takeovers originating from trusted contacts, which could signal exploitation of similar VoIP-layer bugs.[2][3][4] Security analysts note that the worm also highlights how the social graph inside messaging apps—contact lists, group chats, and call histories—can amplify the blast radius of a single flaw once an attacker gains a foothold.[3][4][5]

Calif plans to release a fuller technical analysis of WeWorm at an upcoming security conference, and policy experts argue that cross-border information sharing will be crucial as AI-driven offensive tooling becomes more widely accessible.[1][15] For now, Tencent’s fixes and the absence of observed in-the-wild attacks make WeWorm a cautionary proof-of-concept rather than an active threat, but the incident shows how quickly AI can turn a subtle VoIP bug into a weaponized, self-propagating worm.[1][2][6]

References

  1. “Zero-click” WeChat worm could hijack accounts and …
  2. WeWorm: Zero-Click WeChat Worm Hijacks iOS and Android
  3. WeWorm: Zero-Click Worm Exploits WeChat Calls – ThreatCluster
  4. WeWorm – First 0-Click Worm Spreading Through WeChat …
  5. WeWorm: Zero-Click-Wurm gefährdete über eine Milliarde WeChat-Konten
  6. Zero-Click AI Worm Can Hack WeChat Accounts Via Calls
  7. AI-Created ‘WeWorm’ Exploited WeChat, Tencent Patched Flaw
  8. “Zero-Click” WeChat Worm Could Hijack Accounts and …
  9. Remote Code Execution in WhatsApp VoIP Stack – Mallory.ai
  10. CVE-2019-3568 is a vulnerability in WhatsAppPublished on May 14, 2019
  11. CVE-2019-3568 – Debian Security Tracker
  12. NYT: Researchers Build AI-Powered Zero-Click Worm That …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply