Research · curated 14 Sep 2026

WeChat's 1.4 Billion Users Faced a Dangerous Security Flaw. AI Helped Turn It Into a Self-Spreading Worm.

Coverage timeline

discovered calif.io primary 8 Sep 2026ibtimes.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

WeWorm shows how advanced AI models can dramatically compress the effort needed to build a self-spreading, exponentially scaling worm against a platform with 1.4 billion users, illustrating the growing risk of AI-accelerated exploit and malware development.

Researchers at Calif, a Palo Alto cybersecurity firm, demonstrated WeWorm, a proof-of-concept zero-click worm that exploited a flaw in WeChat's voice-calling system to take over accounts across iOS and Android without any user interaction, and used compromised contacts to spread to their address books. The team said it built the tool in about a week with help from open-source and leading U.S. AI models; Tencent confirmed and fixed the flaw by August 28 and said no users were affected.