Researchers at security firm Calif have demonstrated a self-spreading worm that can take over a WeChat account through nothing more than an incoming call — the target never has to answer, tap a link, or touch the phone. The company says artificial intelligence helped it find the underlying bug and write the first working exploit in roughly two days.

The demonstration, reported September 8 by The Hacker News and The New York Times, shows how dramatically AI is compressing the timeline for developing serious attack tools. No attacks using the flaw have been reported, and Tencent says the exploit has been blocked for all users since late August — but as AI security news has chronicled throughout 2026, AI-accelerated exploitation is moving from theory to practice.

A Worm That Spreads by Ringing

The attack works over WeChat's calling feature. The worm takes over the victim's WeChat account when their phone receives a call from the attacker — even if the call goes unanswered, and even if the phone is simply ringing on a table across the room. Answering does not help: Calif says the victim hears nothing and the exploit still succeeds. Declining the call stops that attempt, but an attacker can simply try again later, for instance while the target sleeps.

There is one constraint: the caller must already be one of the target's WeChat contacts. Calif argues that is barely a barrier in practice, because once one contact is compromised, the extra trust WeChat places in contact-to-contact communication works in the attacker's favor. Each hijacked account becomes a new launch point.

The demonstration showed exactly that chain reaction. One Android phone called an iPhone and took over its WeChat account while the phone was still ringing. The newly compromised iPhone then called a second Android phone and seized control of it the same way.

Once the exploit runs, the attacker gains full control of the WeChat account — reading and sending messages, making calls, and acting as the account's owner. Control of the phone itself is not included, but for an app whose single listing covers payments, official accounts, and mini programs, account takeover is a serious outcome on its own. Tencent reported a combined 1.439 billion monthly active users for WeChat and Weixin as of June 30, 2026.

The AI-Accelerated Timeline

The most consequential detail may be how fast this came together. According to Calif, its team worked with AI to discover the bug and produce the first exploit capable of running code on a phone in about two days; building the worm took another week.

The company's own published timeline is more conservative but still striking: its engineering team identified the bug on July 23, completed the first Android exploit on July 30, and demonstrated the working worm on August 11. The Hacker News notes the shorter figures may count only active working time — but either way, the distance from initial discovery to a self-propagating zero-click worm was measured in weeks, not the months or years such capabilities traditionally required.

Security researchers have warned for two years that large language models would lower the barrier to exploit development. This case is a concrete data point: the AI did not replace the engineers, but it materially accelerated both vulnerability discovery and weaponization.

Tencent's Quiet Fix

Calif reported the flaw to Tencent in July. The company says Tencent has since mitigated the exploit for all users, and that on August 28 it confirmed the block was being enforced on Tencent's servers — meaning protection does not depend on users installing anything.

Tencent shipped WeChat version 8.0.77 for Android and 8.0.76 for iOS on August 21, according to its own release log, and those releases mitigated the bug per Calif. Notably, Tencent has published no security advisory about the flaw. Its release notes describe the updates only as bug fixes, and no CVE identifier had been assigned as of September 8. The Hacker News contacted both companies for comment.

Neither company has said which WeChat versions were affected, whether the flaw extended to WeChat clients on HarmonyOS, Windows, Mac, or Linux, or whether it was ever exploited in the wild. Calif says no attacks have been reported — and that users have no way to check whether they were targeted, since a missed call that silently fails may leave no trace.

What It Means for Mobile Security

Zero-click attacks of this class have mostly been associated with well-resourced spyware vendors operating against small numbers of high-value targets. A worm — attack code that spreads itself from victim to victim — changes the calculus, because it makes the same capability potentially scalable to hundreds of millions of accounts. The New York Times, citing experts, reported the attack could in principle have compromised enormous numbers of devices within hours had it been used maliciously.

Calif is withholding the technical details of the vulnerability and the worm until it can present the full analysis at a security conference, and it has published nothing defenders could search for. That restraint will limit copycats, but it also leaves the broader ecosystem — other messaging apps with similar calling architectures — to audit themselves without a reference.

For users, the practical takeaway is narrow: the server-side block means no action is required, though running the current WeChat release remains advisable. For the security industry, the takeaway is broader. An AI-assisted workflow that turns a standing start into a working zero-click worm in under three weeks is no longer a thought experiment — it is a documented, demonstrated pipeline.

Stay Ahead of AI

Follow the latest on AI security, misuse, and defense developments at AI Buzz Wire.

Read more AI news →