Calif Research Demonstrates AI-Assisted Zero-Click WeChat Worm Developed in Days
Calif Research unveiled WeWorm, a zero-click cross-platform worm capable of taking over WeChat accounts on iOS and Android via unanswered calls. Using AI assistance, researchers discovered the underlying VoIP vulnerability and created a full remote code execution (RCE) exploit and worm in just over a week. The research highlights a dramatic shift in cyber capabilities, showing how AI can compress complex exploit development that traditionally took security teams months into mere days. It underscores the urgent need for defensive security practices to evolve rapidly to counter AI-augmented threat development. The exploit targets a VoIP vulnerability that executes while the victim's phone is ringing, requiring no interaction or answered call from the user. Calif Research responsibly disclosed the bug to WeChat's owner, Tencent, in July 2026, which implemented a server-side mitigation prior to public disclosure.
## BACKGROUND
A zero-click exploit is a severe security vulnerability that compromises a device without requiring any victim action, such as clicking a link or opening an app. A computer worm is self-replicating malware designed to automatically spread across network connections to infect other vulnerable systems.