Research · curated 14 Sep 2026
WeChat's 1.4 Billion Users Faced a Dangerous Security Flaw. AI Helped Turn It Into a Self-Spreading Worm.
First reported calif.io
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
WeWorm shows how advanced AI models can dramatically compress the effort needed to build a self-spreading, exponentially scaling worm against a platform with 1.4 billion users, illustrating the growing risk of AI-accelerated exploit and malware development.
Researchers at Calif, a Palo Alto cybersecurity firm, demonstrated WeWorm, a proof-of-concept zero-click worm that exploited a flaw in WeChat's voice-calling system to take over accounts across iOS and Android without any user interaction, and used compromised contacts to spread to their address books. The team said it built the tool in about a week with help from open-source and leading U.S. AI models; Tencent confirmed and fixed the flaw by August 28 and said no users were affected.