AI-Assisted WeChat Worm Put 1 Billion Accounts at Potential Risk

Researchers used AI to build WeWorm, a zero-click WeChat exploit that could hijack accounts through unanswered calls before Tencent mitigated the flaw.

Sep 9, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Security company Calif said it created a proof-of-concept worm that could hijack WeChat accounts on iPhones and Android phones without requiring recipients to answer a call or interact with their devices. The attacking account had to be on the victim’s friend list, but a compromised contact could then use that trusted connection to spread the worm.

The attack, dubbed WeWorm, exploited a memory corruption flaw in WeChat’s voice-over-IP, or VoIP, system. Once an account was compromised, the attacker could read and send messages, make calls and use the account to target contacts.

“Exploitation takes only seconds, and gives us full control of the WeChat account,” the firm wrote in its disclosure. “We can read and send messages, make calls, and act on the victim’s behalf.”

Calif demonstrated the attack across three phones: A Pixel 10a called an iPhone 17e, which was compromised while the call was still ringing. The infected iPhone then called another Pixel 10a and compromised it in the same way.

“Attacker calls victim, victim becomes attacker, victim calls the next victim,” Calif explained. The potential reach was enormous. Tencent reported more than 1.4 billion combined monthly active users for Weixin and WeChat, while Calif said an attacker exploiting the worm could potentially compromise over a billion phones or accounts. That figure was a theoretical estimate rather than a confirmed count of vulnerable devices.

AI cut the development time

The more unsettling part was how quickly Calif said it moved from discovery to a working exploit. The company said its AI systems found the vulnerability in July. Its engineers produced the first remote code execution exploit in about two days, then built the worm in another week. Calif said a project of this scale would previously have required a larger team and months of work. “AI can already do most of the work here,” the company said.

The researchers did not identify the AI models used, saying they relied on a mix of open-source and leading commercial systems.

Calif reported the vulnerability to Tencent on July 24. Tencent released WeChat 8.0.77 for Android and 8.0.76 for iOS on Aug. 21, and Calif confirmed Aug. 28 that the exploit had also been mitigated server-side for all users. 

Tencent told The New York Times it had no reason to believe any users were affected. The demonstration nevertheless showed how quickly an AI-assisted vulnerability discovery could become a self-spreading exploit.

The bigger security problem

Advertisement

WeWorm shows how AI could change the economics of vulnerability research. The immediate danger is not simply that AI can discover a bug. It is that the time between finding a vulnerability and turning it into something capable of spreading could shrink dramatically.

That matters for messaging platforms because trust is built into their design. WeChat gives saved contacts greater privileges, but a compromised account can turn that trusted relationship into a delivery system for the next attack.

There is also an important limit to the demonstration: WeWorm did not automatically provide complete control of a phone by itself. Calif said additional Android and iOS vulnerabilities would be needed for a full device takeover.

Still, the episode highlights a new race between attackers and defenders. Calif argues that slowing AI development would miss the underlying problem because the vulnerabilities already exist.

“What AI changed is that we can find and fix them fast,” the company said. Tencent’s server-side mitigation means users do not need to take action against this particular exploit. For security teams, the broader lesson is that AI could shorten the time between vulnerability discovery and weaponization, making faster disclosure, mitigation and patch deployment increasingly important.

Read more: OpenAI slowed frontier-model training as Astra approached a critical cybersecurity threshold, underscoring concerns that advanced AI could accelerate vulnerability discovery and exploitation.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.