Security research firm Calif has unveiled WeWorm, a zero-click worm capable of spreading through WeChat calls on iOS and Android devices. The worm exploits a memory corruption vulnerability in WeChat’s VoIP stack, allowing an attacker to take control of a victim’s account simply by initiating a call. The victim does not need to answer or interact with the call for the exploit to succeed.
WeChat, widely used across China and Chinese communities worldwide, serves as a critical communication platform. The worm’s ability to hijack accounts and propagate by calling contacts poses a threat to over a billion users, potentially disrupting personal and professional networks.
In a demonstration, researchers used three phones to show how the worm spreads: starting from an Android device acting as the attacker, they compromised an iPhone during an incoming call, then used the infected iPhone to infect another Android phone. This chain reaction illustrates how a compromised account can be weaponized to attack others.
The exploit requires the attacker to be on the victim’s friend list, but Calif notes this barrier is minimal since attackers can first compromise one contact and then use their account to reach others. Once inside, attackers gain full control over the WeChat account, including reading and sending messages and making calls.
Calif’s team leveraged artificial intelligence to identify the vulnerability and develop a remote code execution exploit within days, significantly accelerating what traditionally would have taken months. They emphasize that while AI lowers the barrier for attackers, it also empowers defenders to find and fix vulnerabilities more rapidly.
The researchers responsibly disclosed the bug to Tencent in July 2026. Tencent responded by releasing updates that have mitigated the exploit for all users. Calif praised the collaboration and called for international cooperation among governments and private industry to enhance security in the era of AI.
The underlying vulnerability is a memory corruption flaw in WeChat’s VoIP implementation. Calif plans to release a detailed technical analysis at an upcoming conference. They are also investigating similar attack surfaces in other messaging applications, advocating for industry-wide efforts to reduce such risks.
This research highlights the evolving threat landscape as AI accelerates both offensive and defensive cybersecurity capabilities. It underscores the importance of proactive vulnerability discovery and patching to protect users of widely adopted communication platforms.