AI accelerated the development of the first zero-click WeChat worm, WeWorm. Tencent has fixed all vulnerabilities.
2026-09-08 17:59Cybersecurity🔥 49.3 heat score
2sources
1days unfolding
49.3heat score
4mentions
SummaryAI generated
The cybersecurity company Calif used artificial intelligence to develop the first “zero-click” worm virus, WeWorm, for WeChat, in about two weeks. The virus spreads through WeChat calls and can take just a few seconds to take control of applications and spread to other victims. In July this year, Calif’s team discovered a memory corruption issue in WeChat’s VoIP protocol stack. With AI assistance, they managed to create a remote code execution vulnerability in just two days, and then spent seven days developing the virus. Tencent has confirmed that the vulnerabilities have been fixed on both the client-side (Android 8.0.77, iOS 8.0.76) and server-side, and all users are currently unaffected. Calif noted that AI significantly shortened the development cycle for such large-scale worms; work that previously required a large team to complete over months can now be done with AI.