Skip to content

AI-built 'WeWorm' Could Rapidly Hack WeChat, NYT Reports

techSep 8, 20261962

Researchers at security firm Calif built a zero-click mobile worm they call WeWorm that exploited a WeChat vulnerability to spread via incoming calls and fully compromise accounts on both IOS and Android. The team demonstrated WeWorm infecting three test phones and said the prototype took a little more than a week to build. The New York Times reported experts estimated the worm could have compromised hundreds of millions of devices within hours had it been unleashed. Calif and reporting by Dustin Volz of the New York Times say Tencent has patched the flaw on client builds (Android 8.0.77 and IOS 8.0.76) and on the server side. Calif described WeWorm as the first known worm capable of leaping across IOS and Android without user interaction. Researchers presented the work to highlight how quickly AI models can generate potent exploits and warned about the speed and scale at which similar automated malware could be developed if vulnerabilities remain unpatched.

1 source