WeWorm was a proof of concept worm that Calif said could hijack a WeChat account during an incoming call—without the recipient answering—and then spread by calling that account’s contacts. The demonstration showed account level compromise across iOS and Android, not an automatic full device takeover.
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What was WeWorm, the AI-built computer worm developed by Palo Alto-based security firm Calif that exploited a memory-corruption flaw in WeCh. Article summary: WeWorm was Calif’s proof-of-concept, self-propagating zero-click worm for WeChat: an incoming voice call exploited a memory-corruption bug in WeChat’s VoIP call-handling code, taking over the target’s WeChat account on i. Topic tags: general, general web, user generated, government, academic. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, wate
WeWorm was an AI-assisted, proof-of-concept computer worm built by Palo Alto security firm Calif to demonstrate a serious flaw in WeChat’s voice-calling code. Calif said a specially crafted incoming call could compromise a recipient’s WeChat account in seconds, even if the person never answered or interacted with the phone. The company reported the issue to Tencent before public disclosure, and Tencent deployed mitigations. 10
14
The underlying issue was a memory-corruption vulnerability in WeChat’s Voice-over-IP (VoIP) stack—the component that handles calls. Calif said the exploit could execute while a call was ringing, eliminating the usual need for a victim to click a link, open an attachment, or answer a call. 10
3
That made it a zero-click attack: the vulnerable software processed the call before any meaningful user action was required. Calif has withheld the low-level vulnerability and exploit details, an important safeguard against replication. 10
A worm differs from a one-off account takeover because it can use each newly compromised account to reach further targets. In Calif’s demonstration, the compromised WeChat account could place calls to people in its saved contacts or friend list, attempting the same attack again. 1
10
This contact-based propagation was both powerful and constrained:
Calif demonstrated a chain spanning Android and iOS devices, showing that the propagation concept was cross-platform. Claims that it could reach hundreds of millions of accounts were projections of potential spread through WeChat’s large network—not evidence that such an event occurred. 10
13
Calif described the result as full control of the WeChat account. That could allow an attacker to read and send messages, place calls, impersonate the account holder, and use the account to target additional contacts. 1
8
That is not the same as a complete iPhone or Android operating-system takeover. The demonstrated impact was account-level control; Calif indicated that separate vulnerabilities would be needed to turn that access into full device compromise. 14
According to Calif, its team used AI to find the flaw and write an initial remote-code-execution exploit in about two days, then built the worm demonstration in roughly another week. 10
8
The key implication is not that AI independently launched an attack. Rather, the project illustrates how AI can reduce the time and specialist effort needed for vulnerability research, debugging, exploit iteration, and adaptation. Those same capabilities can also help defenders analyze software and accelerate remediation.
Calif’s public WeWorm account says the team worked with AI, but it does not reliably identify a particular model or coding product. Claims that WeWorm specifically used Claude, GPT, Codex, or another named tool are therefore not supported by the available public disclosure. 10
Calif said it privately reported the vulnerability to Tencent in July. Tencent released WeChat Android 8.0.77 and iOS 8.0.76 on August 21, according to Calif, and Calif later said a server-side mitigation blocked the exploit for all users. Tencent confirmed that the vulnerability could enable remote command execution. 10
14
The distinction between a demonstration and an active campaign matters: public reporting describes WeWorm as a proof of concept, and there is no public evidence that Calif deployed it against real users or that it caused an in-the-wild mass infection. 9
WeWorm is notable because it combined three high-impact properties: zero-click exploitation, self-propagation through trusted contacts, and cross-platform reach. Even with the reported flaw mitigated, the project is a reminder that communications features—especially call handling and other automatically processed content—can become high-value attack surfaces.
For users, keeping WeChat and mobile operating systems updated remains the practical defense. For software teams, the broader lesson is to prioritize memory-safety testing, secure call-processing paths, rapid vulnerability disclosure channels, and defense-in-depth for account recovery and session controls. 10
14
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
WeWorm was a proof of concept worm that Calif said could hijack a WeChat account during an incoming call—without the recipient answering—and then spread by calling that account’s contacts.
WeWorm was a proof of concept worm that Calif said could hijack a WeChat account during an incoming call—without the recipient answering—and then spread by calling that account’s contacts. The demonstration showed account level compromise across iOS and Android, not an automatic full device takeover.