Key Takeaways
- Security researchers at Calif have developed an AI-powered worm called WeWorm that can spread through WeChat calls.
- The worm can take over WeChat accounts without the victim needing to answer the call.
- Tencent has confirmed the vulnerability and fixed the issue, with no evidence of user impact.
Security researchers at Calif have developed an AI-powered worm called WeWorm, capable of spreading through WeChat calls without requiring the victim to answer the call.
The worm can take over WeChat accounts and use them to call additional contacts, allowing the worm to spread further.
The attacker needs to be on the victim’s WeChat friend list to initiate the call, but once the call is placed, the exploit works even if the victim declines it.
If successful, the attacker could gain control of the account, allowing them to read and send messages, make calls, and act as the account owner.
The vulnerability is attributed to a memory corruption flaw in WeChat’s internet calling system, with AI playing a significant role in finding the exploit and developing the worm.
Calif’s researchers spent about two days actively working on the initial exploit and another week developing the worm, with human researchers closely supervising the AI process.
Tencent confirmed the vulnerability after Calif reported it on July 24 and has since released updates to fix the issue, with no evidence of user compromise.
WeChat and Weixin had around 1.439 billion combined monthly active users as of June 30, making the vulnerability particularly concerning due to the potential reach and the common use of WeChat accounts for messaging, payments, and official accounts.
Calif has not released the technical details required to reproduce the exploit, and there are currently no reports of WeWorm being used in a real-world attack.





