Calif Research releases WeWorm, a zero-click WeChat exploit built with AI
Calif Research has released a demo of WeWorm, described as the first zero-click worm capable of spreading through WeChat calls on both iOS and Android devices. The exploit is particularly concerning because it requires no user interaction; victims do not need to answer the call or touch their phones for the infection to succeed. Even if a user answers, they hear nothing, yet the remote code…
Key points
- WeWorm is a zero-click WeChat worm affecting iOS and Android that requires no user interaction to succeed.
- Calif Research used AI to find the bug and write the RCE exploit in two days, significantly faster than traditional methods.
- The team noted that AI can now perform most of the work in building complex worms, with humans providing strategic judgment.
The security firm highlighted the significant role of artificial intelligence in accelerating this threat. Their team used AI to identify the underlying bug and develop the initial RCE exploit in just two days, followed by one week to construct the full worm. This contrasts sharply with previous industry standards, where developing a worm of this scale typically required larger teams working for months. Calif Research noted that while AI handled the bulk of the technical work, human judgment was still essential for determining targets and ensuring safe testing protocols.
This development underscores a growing trend where AI tools are lowering the barrier to entry for creating sophisticated, high-impact security threats. The speed at which these exploits can now be generated suggests that defenders may face increasingly rapid and automated attack vectors in the near future.
Quoting Calif Research
Simon Willison · 10 September 202610th September 2026
Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...]
The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...]
Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week.
A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely.
— Calif Research, WeWorm
Recent articles
This text was published by Simon Willison and written by Simon Willison. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
Comments
via GitHub Discussions