WeWorm: Zero-Click WeChat Worm

Sep 12, 2026 12:49 PM - 4 hours ago 2

WeWorm

At Calif, our ngo is to support the Internet together by occasionally taking it apart. We judge everyone deserves a safe and unafraid Internet, including the group who cannot protect themselves.

Today, we're releasing a demo of WeWorm, the first zero-click worm to dispersed done WeChat calls crossed iOS and Android. This is the first installment successful a bid exploring zero-click onslaught surfaces successful mobile messaging apps.

WeChat is an "everything app" utilized by virtually everyone successful China and by Chinese communities worldwide. Simply by calling a victim, WeWorm tin hijack their relationship and telephone their friends, spreading from telephone to phone. If exploited, actors tin discuss complete a cardinal phones (or accounts), upending livelihoods and breaking communities worldwide.

We built a demo worm pinch 3 phones:

The first Android phone, a Pixel 10a, is the attacker. We utilized it to telephone the 2nd phone, an iPhone 17e, and exploited the bug to return complete its WeChat while it was still ringing. We past utilized the compromised iPhone to telephone the 3rd phone, different Pixel 10a, and took that 1 complete the aforesaid way. Attacker calls victim, unfortunate becomes attacker, unfortunate calls the adjacent victim.

You tin besides watch individual Android and iOS RCE demos.

Exploitation takes only seconds, and gives america afloat power of the WeChat account. We tin publication and nonstop messages, make calls, and enactment connected the victim's behalf. Chained pinch different Android and iOS bugs we've reported and are helping fix, it tin lead to afloat power of the device.

The unfortunate does not request to reply the call, aliases interact pinch their telephone astatine all. Even if they do answer, they perceive nothing, and the utilization still succeeds. Declining the telephone stops that attempt, but the attacker tin simply effort again later, for example, while the unfortunate is asleep.

This utilization requires the attacker to beryllium connected the victim's friend list. But that's not overmuch of a barrier: an attacker tin discuss 1 of your friends first and usage their relationship to scope you.

WeChat, for illustration galore messaging apps, gives trusted contacts much privileges. But erstwhile 1 interaction is compromised, that spot useful against you.

Sophisticated attackers person galore ways to do this. They could utilization different app, summation guidelines entree utilizing techniques for illustration those successful OEMpocalypse, return complete the victim's WeChat app, and usage it to onslaught you.

Working pinch AI, our squad recovered the bug and wrote the first distant codification execution (RCE) utilization successful astir 2 days. Building the worm took 1 much week.

A worm astatine this standard utilized to beryllium the benignant of point that took a larger squad months. AI tin already do astir of the activity here. Our squad provided the judgement astir what to target and really to trial it safely.

We are publishing our findings to raise nationalist awareness. These capabilities person existed for a agelong clip successful the hands of well-funded, blase actors. What's different now is that AI is putting these capabilities successful the hands of little skilled actors, leaving mean users astatine unprecedented risk.

All it takes is 1 laboratory mishap aliases a personification who grabs a half-finished version, to unleash thing for illustration WeWorm into the world earlier anyone is ready. WannaCry sewage retired that way, from tooling that escaped early and deed hospitals.

The easy guidance is to blasted AI and effort to curtail its further development. We deliberation that is the incorrect lesson. The vulnerabilities are already retired there. What AI changed is that we tin find and hole them fast. We judge location are much bully guys than bad guys, and if they're paying attention, AI gives the bully guys the precocious hand.

We reported the WeChat bug to Tencent successful July. As of today, they person mitigated our utilization for each users. We'd for illustration to convey Tencent for a successful collaboration.

We dream this activity is an illustration of what we tin execute together. It is simply a telephone for the United States, China, and different governments to activity together and collaborate pinch backstage manufacture connected processing and deploying AI to make the world safer for everyone.

The bug

The bug is simply a representation corruption rumor successful WeChat's VoIP stack. We're withholding the method specifications for now. We scheme to coming the afloat study astatine an upcoming conference.

This circumstantial WeChat bug is 1 lawsuit of the galore unconventional onslaught surfaces that are coming crossed galore messaging apps. We're conducting much of this investigation crossed different apps and onslaught surfaces, while moving pinch app developers connected onslaught aboveground reduction. This whitethorn return an industry-wide effort, since immoderate of it depends connected the level owners. Once that activity is further along, we'll stock our progress, including the method specifications of this WeChat bug.

Disclosure timeline

  • Sometime successful July, 2026: Our AI discovered the bug.
  • July 23: Our engineering squad became alert of the bug.
  • July 24: We submitted the bug to Tencent.
  • July 25-28: Our WeChat accounts were banned.
  • July 29: Our WeChat accounts were unbanned.
  • July 30: We completed the first Android RCE exploit.
  • August 2: We completed the iOS RCE exploit.
  • August 11: We completed the polished worm demo crossed Android and iOS.
  • August 21: Tencent published Android 8.0.77 and iOS 8.0.76 that mitigated the bug.
  • August 26: Tencent notified america that they're assessing the issue.
  • August 28: We confirmed that our utilization was mitigated connected the server broadside for each users.
  • September 3: We shared our method study and moving exploits pinch Tencent.
  • September 4: Tencent confirmed that the vulnerability could beryllium exploited for distant bid execution.
  • September 8: We published this article alongside sum from The New York Times.
More