AI Helps Researchers Build WeChat Zero-Click Worm in Days
Tencent’s WeChat combines messaging, calls, payments and mini programs, making any remotely exploitable flaw a potentially systemic threat. WeChat and its Chinese counterpart Weixin had 1.439 billion combined monthly active accounts as of June 30, 2026. Security firm Calif found a memory-corruption bug in the app’s VoIP stack and built WeWorm, which could compromise an account while a call from an existing contact was still ringing, then spread through the victim’s contacts across iOS and Android.
Calif disclosed the research on Sept. 8, 2026, saying AI found the flaw in July and helped produce the first remote-code-execution proof of concept in about two days after engineers began work on July 23. The firm completed an Android exploit by July 30, an iOS version by Aug. 2 and a polished cross-platform worm demonstration by Aug. 11. Tencent released Android version 8.0.77 and iOS version 8.0.76 on Aug. 21, while Calif confirmed server-side mitigation for all users on Aug. 28. No exploitation in the wild has been reported.
All Coverage
2 original reportsThe Backstory
The history behind this eventThis is the first time the radar has seen this story
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →