Calif, a security company based in Palo Alto, California, published its WeWorm research on 8 September 2026. The firm describes it as the first zero-click worm to spread through WeChat calls across iOS and Android, built around a memory corruption flaw in the app's voice-over-IP stack. The published demo used three phones: a Pixel 10a acting as the attacker placed a call to an iPhone 17e, and the exploit took over the target's WeChat account.
The delivery condition is the severe part. The victim does not tap, answer, or touch the phone; the incoming call alone is enough, per techlicious.com. Once an account is hijacked, the worm calls the victim's contacts, and the cycle repeats on each new device. That propagation loop is what separates a worm from an ordinary remote exploit: each compromise manufactures the next one without further attacker effort.
The addressable population is large. WeChat is used by virtually everyone in China and by Chinese communities worldwide, according to Calif's own write-up at calif.io. Both calif.io and qz.com state that exploitation could compromise over a billion phones or accounts, and qz.com adds an estimate of hundreds of millions of devices reached within hours. Those figures describe ceiling and speed respectively; neither has been demonstrated at scale.
Calif built the working worm in under two weeks, per the title of its own research page. qz.com reports the firm did so with significant assistance from AI, and bankinfosecurity.com independently describes the flaw as found with AI. Three outlets carrying the AI attribution suggests it is central to how Calif wants the work understood, not incidental color in the disclosure.
The compressed timeline is the analytically interesting number. Memory corruption work in a VoIP stack has historically demanded specialized reverse-engineering skill and weeks of manual effort per target. A two-week turnaround on a cross-platform worm, with AI in the loop, suggests the labor curve for this class of bug is flattening. That is an inference from the stated dates, not a claim Calif makes explicitly about its tooling.
The evidence does not specify which models Calif used or which build stages AI handled — bug discovery, exploit development, or both. The record is silent there, and Calif's write-up frames the worm as the first installment in a series exploring zero-click attack surfaces in mobile messaging apps, under a mission statement about keeping the Internet together by occasionally taking it apart. The methodology details presumably arrive with later installments.
Tencent, which owns WeChat, has already patched the flaw, according to techlicious.com's 8 September report. Bankinfosecurity.com's coverage followed on 9 September, describing the bug as requiring no user interaction. The record does not state when Calif reported the flaw to Tencent or how long the fix took; the disclosure timeline before publication is not in the evidence.
What was at risk exceeds data theft. A hijacked WeChat account is an identity, a payment rail, and a social graph in one credential, and the worm's design weaponized that graph as its own distribution channel. Calif's write-up states that exploitation would upend livelihoods and break communities worldwide. The open question is operational: a worm that spreads through contact lists turns containment into a race between patch rollout and propagation.
Two signals are worth tracking. First, whether Tencent's patch has reached the full installed base, since a worm dormant in unpatched clients remains live; the evidence does not address rollout coverage. Second, whether other messaging platforms share the structural weakness — an unauthenticated VoIP parsing path reachable before a call is answered. Calif has committed to a series on zero-click surfaces in mobile messaging, which suggests WeChat was the opening case rather than the survey's conclusion.
Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.
The AI news that matters — in your inbox by 07:30 CET. Free, no spam.