WeWorm: an AI-assisted zero-click worm demonstrates full WeChat account takeover on Android and iOS from a single unanswered call
Calif builds a self-propagating zero-click WeChat worm with AI help in about nine days; Tencent fixed it before disclosure
Analysis
Calif, a US offensive-security research firm, published a working demonstration of WeWorm on 2026-09-08: a zero-click worm that takes over a WeChat account on Android or iOS through a single incoming voice or video call, exploiting a memory-corruption bug in WeChat's VoIP call-signaling stack (Calif is withholding the specific bug detail pending a conference talk) (Calif, 2026-09-08). The exploit fires while the call is still ringing and requires no answer and no interaction: "The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds" (Calif, 2026-09-08). The only prerequisite is that the caller already sits on the victim's WeChat contact list, and because WeChat grants saved contacts additional trust, a first compromised account can call and take over further contacts on its own: Calif demonstrated hop-to-hop propagation across three physical devices, each full takeover (read and send messages, place calls, act as the account owner) completing in seconds (Calif, 2026-09-08; Help Net Security, 2026-09-08).
The transferable finding is a capability data point, not an active threat. Calif states an AI-assisted workflow found the bug and produced the exploit fast, "Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days" (Help Net Security, 2026-09-08), with the self-propagating worm built in one further week, work it says a human team previously needed months for. This is responsibly-disclosed research, not in-the-wild activity: Calif reported the flaw to Tencent on 2026-07-24, Tencent shipped client fixes (Android 8.0.77, iOS 8.0.76) on 2026-08-21 and, per Calif, blocked the exploit on its servers for all users by 2026-08-28, requiring no user install (The Hacker News, 2026-09-08). No CVE has been assigned and Tencent has published no advisory: "Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent's security response site, which lists the latest announcement as April 2022" (The Hacker News, 2026-09-08), and Calif declined to say whether the underlying bug, versus its specific exploit, is fixed (The Hacker News, 2026-09-08).
Cited evidence
The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds.
Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days.
Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent's security response site, which lists the latest announcement as April 2022.
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.