Security Firm Builds Zero-Click WeChat Worm Spreading Across iOS and Android; Tencent Confirms Fix
US security firm Calif developed WeWorm, a zero-click worm proof-of-concept targeting WeChat that can hijack accounts via a single call without user interaction. It is the first known zero-click worm spreading between iOS and Android. Tencent investigated, deployed a server-side fix for all users, and found no evidence of exploitation. Calif disclosed the issue to White House officials before publication.
Calif, a US cybersecurity company based in Palo Alto, California, has developed a zero-click worm attack proof-of-concept named WeWorm that targets WeChat. The company's research team demonstrated that a single phone call to a WeChat contact could hijack the target's account within seconds, without requiring any action from the victim. Calif said this is the first known zero-click computer worm capable of spreading between Apple's iOS and Android systems. After receiving Calif's disclosure, Tencent investigated the issue and completed a fix, which has been deployed to its servers and is effective for all users. Tencent stated that there is currently no evidence the vulnerability was exploited or that users were affected, and no app update is required.
According to Calif's research summary, WeWorm exploits WeChat's trust mechanism for saved contact phone numbers. Once a WeChat account is compromised, the worm can read and send messages, make calls, and control the victim's account, while automatically propagating to other numbers in the account's contact list. The attack succeeds if the targeted user answers the call or lets it ring; only rejecting the call within a few seconds after the first vibration can prevent the intrusion. Calif also noted that, combined with other security vulnerabilities, an attacker could gain full control of the victim's phone through a compromised WeChat account.
Calif said its research team used artificial intelligence to discover the WeChat vulnerability in two days and then spent a week building the worm. The researchers used a combination of open-source AI models and leading US models, but did not disclose specific model names. In a related case, in May 2026, Calif used an earlier version of an AI model to bypass security mechanisms in Apple's macOS operating system. These AI systems require integration with human cybersecurity expertise to discover and exploit vulnerabilities and are not fully autonomous in carrying out attacks.
Before publicly disclosing WeWorm, Calif briefed White House officials, who confirmed receipt of the notification. Tencent's 2026 disclosures indicate that WeChat has more than 1.4 billion monthly active users, the vast majority based in China. Recently, more than 100 major technology companies, including OpenAI, jointly signed an open letter. In April 2026, Anthropic released a new AI model and stated that it had identified thousands of zero-day vulnerabilities across major operating systems and browsers. Subsequently, Anthropic and OpenAI restricted access to their latest and most powerful models to select companies and government agencies.