A cybersecurity startup has created a hacking tool that can take over Android and iOS phones through nothing more than an incoming WeChat call that victims don't need to answer. Calif, a Palo Alto–based firm, disclosed the tool—called WeWorm—in a report dated September 8, calling it "the first zero-click worm to spread through WeChat calls across iOS and Android." The researchers tested WeWorm on Google Pixel 10a and iPhone 17e devices, exploiting a vulnerability they discovered in July within WeChat, the Chinese super-app used for messaging, calls, payments, and transactions.
The flaw Calif uncovered is a memory corruption bug in WeChat's voice-over-IP stack that takes advantage of the permissions trusted contacts have when connecting with other app users. Researchers found the vulnerability using a mix of large language models, including open-weight systems and closed-source models from US frontier labs, though they didn't name which ones. After reporting the issue to Tencent—WeChat's parent company—Calif's account was initially banned, but the Chinese firm later acknowledged that exploiting the bug could enable remote command execution. Tencent released patched versions on Android (8.0.77) and iOS (8.0.76). Calif built working exploits for vulnerable WeChat apps in two days, then spent an additional week integrating them into the WeWorm tool.
WeWorm gives attackers complete control over a targeted WeChat account, allowing them to read and send messages, place calls, and act as the victim. "The victim does not need to answer the call or interact with their phone at all," the researchers wrote. "Even if they do answer, they hear nothing, and the exploit still succeeds." Declining the call blocks that specific attempt, but attackers can simply retry later—potentially while the victim sleeps. While the exploit requires the attacker to be on the victim's friend list, this isn't a significant obstacle because "an attacker can compromise one of your friends first and use their account to reach you," the report notes. When chained with other Android and iOS bugs, WeWorm can lead to full device control.
The speed at which Calif developed WeWorm highlights how artificial intelligence is changing offensive cybersecurity work. "A worm at this scale used to be the kind of thing that took a larger team months," the researchers concluded. "AI can already do most of the work here." Their team provided judgment on what to target and how to test it safely, but the technology handled much of the heavy lifting. The fact that a startup could build a cross-platform, zero-click exploit in just over a week—using off-the-shelf language models—suggests these capabilities are becoming more accessible. For WeChat's billion-plus users, the immediate fix is updating to Tencent's patched versions, though the worm's design shows how social graphs can be weaponized: once a single trusted contact is compromised, entire networks become vulnerable through automated propagation. Organizations relying on WeChat for business communications face particular risk until updates are universally deployed, since the attack leaves no trace that would prompt users to investigate. If similar vulnerabilities exist in other messaging platforms with comparable user bases, the window between discovery and widespread exploitation may be narrowing faster than enterprise security teams can adapt. The report doesn't predict whether other apps harbor comparable flaws, but the tooling and techniques Calif demonstrated are unlikely to remain unique for long.

