Mark RadarMARK RADAR
About
EN
Sign in
Event File AI

AI Helps Researchers Build WeChat Zero-Click Worm in Days

2 reports · First detected 2026-09-09 · Last active 2026-09-14

Tencent’s WeChat combines messaging, calls, payments and mini programs, making any remotely exploitable flaw a potentially systemic threat. WeChat and its Chinese counterpart Weixin had 1.439 billion combined monthly active accounts as of June 30, 2026. Security firm Calif found a memory-corruption bug in the app’s VoIP stack and built WeWorm, which could compromise an account while a call from an existing contact was still ringing, then spread through the victim’s contacts across iOS and Android.

Calif disclosed the research on Sept. 8, 2026, saying AI found the flaw in July and helped produce the first remote-code-execution proof of concept in about two days after engineers began work on July 23. The firm completed an Android exploit by July 30, an iOS version by Aug. 2 and a polished cross-platform worm demonstration by Aug. 11. Tencent released Android version 8.0.77 and iOS version 8.0.76 on Aug. 21, while Calif confirmed server-side mitigation for all users on Aug. 28. No exploitation in the wild has been reported.

All Coverage

2 original reports

The Backstory

The history behind this event

This is the first time the radar has seen this story

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)