Calif, a security firm based in Palo Alto, California, published a research report on Sept. 8 saying its team, with help from AI, found a memory corruption bug in WeChat’s internet voice calling component and turned it into a zero-click worm called WeWorm. The attack path in the report was blunt: an attacker only has to place a WeChat voice call to a target. The target does nothing at all, and the account can still be hijacked, then used to call the target’s friends and keep the spread going.
Calif said that if the flaw had been used in real attacks, "an actor could compromise more than a billion phones or accounts." Tencent released a patched version on Aug. 21 and finished server-side blocking by late August.
A call alone was enough, and the victim did not need to answer
Calif described the attack like this: "Just by calling the victim, WeWorm can hijack the account and call that person’s friends, spreading from phone to phone."
On what the victim had to do, the report left little room for doubt: "The victim does not need to answer and does not need to interact with the phone at all. Even if the call is answered, no sound is heard, and the attack still succeeds." It added that a full account takeover took only a few seconds.
Calif said the spread worked like a chain. The attacker calls the victim. Then the victim becomes the attacker. Then that victim calls the next victim. But there was one limit: the caller had to already be on the target’s friend list. Calif said that once an account was compromised, it could attack its own contacts and move laterally from there.
The company also published a cross-platform demonstration video showing the worm spreading from a Pixel 10a to an iPhone 17e, and then back to another Pixel 10a.
Flaw sat in the voice calling component, with no CVE yet assigned
The bug was in WeChat’s internet voice calling program, and Calif classified it as memory corruption. For now, Calif said it is not releasing the technical details and will present a full technical briefing at a later conference.
So far, no CVE number has been assigned. Tencent’s August earnings report for the second quarter of 2026 said combined monthly active accounts for Weixin and WeChat reached 1.439 billion as of June 30.
Calif says AI helped produce the first remote code execution exploit in about two days
The report included a development timeline. Calif wrote: "Working with AI, our team found the vulnerability and wrote the first remote code execution exploit in about two days." Building the full worm took about another week.

According to the timeline, AI found the bug in July, and the engineering team learned about it on July 23. An Android remote code execution exploit was completed on July 30. The iOS version was finished on Aug. 2. A full demo-ready worm was completed on Aug. 11.
Calif also made a point of separating human judgment from AI output: "Our team provided the judgment, deciding what to target and how to test safely." Thai Duong, the company’s CEO, told The Next Web that the team had to "watch the entire process the whole time" to get to a working worm. The report did not say which company’s AI model was used.
Unlike earlier AI-assisted security cases, this one involved a self-spreading worm
ABMedia pointed to two earlier cases in the same general lane: Claude finding a kernel flaw in Apple’s macOS 26.5, and Anthropic’s Mythos model breaking through macOS security protections in five days. Those cases were about finding bugs and bypassing protections. This time, Calif’s disclosure was about a worm that could spread between devices by itself, paired with a cross-platform demonstration video.
Four weeks from disclosure to patch, with server-side mitigation already in place
Calif’s timeline said the team reported the flaw to Tencent on July 24. From July 25 to July 28, accounts used by the researchers for testing were suspended. Then they were restored on July 29.
Tencent released patched versions on Aug. 21: Android was updated to 8.0.77, and iOS to 8.0.76. Calif said the mitigation measures were confirmed effective between Aug. 26 and Aug. 28. On Sept. 3, Calif gave Tencent technical analysis. On Sept. 8, the company published the report. That same day, New York Times reporter Dustin Volz published a report on the issue.
According to Calif, Tencent’s server-side block applied to all users and required nothing from users themselves. The report also said the fix took four weeks from disclosure to release, plus one more week to confirm the server-side mitigation.
Calif said full technical details will be released at a later conference. Tencent has confirmed the flaw existed and said remediation is complete. It has not published any findings on affected accounts.

