0.00 Is a Lab Number. Grok's Incident Standard Is Still Missing.
xAI's Grok 4.20 card reports a 0.00 chat violation rate. The same PDF shows AgentHarm at 0.30. Production, a DSA case, and AB 316 already bind operators.
Calif demoed a zero-click WeChat account worm via an incoming call. Tencent blocked the exploit for all users by 28 August. There is no CVE and no reported outbreak.
WeWorm is Calif's demo of a zero-click WeChat account takeover. An incoming call from a friend-list contact was enough; the victim did not have to answer. Calif says AI found the VoIP-stack memory bug and a first RCE in two days, then spent a week on a three-phone worm. Tencent mitigated the exploit for all users by 28 August.
The New York Times headline is that AI models built a worm that could rapidly hack WeChat accounts. Calif is the firm that did the work, and their write-up is the document to file. The demo is a zero-click WeChat account takeover from an incoming call. The victim does not have to answer. Tencent, per Calif, has already blocked the exploit for every user. Nobody has published a CVE, and nobody has published an outbreak.
High Wormable account takeover on iOS and Android from a friend-list call, demonstrated in a lab, mitigated on Tencent's servers. High because of the trust graph, not because this is a confirmed campaign.
Calif is a California security firm. Thai Duong, who ran Google's crypto work on BEAST, CRIME, and POODLE, is the chief. The research page published today names the demo WeWorm and calls it the first zero-click worm to spread through WeChat calls across iOS and Android.
The trigger is an incoming WeChat call. The target does not need to answer or touch the phone. If they do answer, they hear nothing and the exploit still lands. Declining ends that attempt. The attacker can call again later, including while the target is asleep.
The caller has to be on the target's friend list. That is a real gate, and it is a thin one once the first account falls. WeChat gives contacts extra privileges. A compromised friend is a trusted caller. Calif's demo is that hop: a Pixel 10a calls an iPhone 17e and takes WeChat while it is still ringing, then that iPhone calls a second Pixel 10a the same way.
What the exploit buys, on Calif's description, is the WeChat account: read and send messages, place calls, act as the user. WeChat is not only chat. Payments, official accounts, and mini programs sit in the same session. Calif says chaining this with other Android and iOS bugs they have reported can reach the device. Those other bugs are not in today's public write-up. Treat device-wide compromise as a claimed follow-on, not as the demo.
The class is memory corruption in WeChat's VoIP stack. Calif is holding the rest for a conference. We are not reconstructing the call. The operator fact is the trust graph plus an unanswered ringing path.
Calif's marketing line is that AI found the bug and wrote the first RCE in about two days, and that the worm took one more week. Their own dates are longer than that slogan if you count calendar time from 23 July to 11 August. The Hacker News noted the gap. Keep both: the compressed working-time claim, and the disclosure clock Tencent actually ran.
The Times story, by Dustin Volz, is filed under US politics and tags OpenAI Labs, Tencent, and WeChat. Calif is an OpenAI Daybreak partner. The research post does not name a model. Do not brief this as an unattended GPT worm. Brief it as a red team that used AI to compress the find-and-exploit loop on a messaging VoIP stack, then spent a week turning two RCEs into a cross-platform hop.
| Product | Affected | Fixed in |
|---|---|---|
| WeChat Android | Unpublished. Calif tested a Pixel 10a. | 8.0.77 (2026-08-21) plus server-side block by 28 Aug, per Calif |
| WeChat iOS | Unpublished. Calif tested an iPhone 17e. | 8.0.76 (2026-08-21) plus server-side block by 28 Aug, per Calif |
| WeChat HarmonyOS / desktop | Not stated by Calif or Tencent | Not stated |
Tencent's own update log confirms the 21 August dates. The iOS note is "fixed some known issues." There is no security bulletin on Tencent's response site for this bug. The Hacker News checked. So did we: the versions exist; the advisory does not.
If you run WeChat or Weixin on a phone you care about:
Calif is right that WannaCry got out of a lab. They are also right that this write-up is a disclosure, not a drop. The missing artefacts are a CVE, an affected-version list, and a Tencent note that uses the word security. Until those exist, the operator action is update, and the briefing action is not to confuse a three-phone demo with a worm already in the wild.
Calif says Tencent blocked this exploit on the server for all users as of 28 August, so the block does not depend on you installing a build. Running a current client is still the safer default. Official logs list Android 8.0.77 and iOS 8.0.76 on 21 August. Neither firm has said whether HarmonyOS or desktop clients were in scope.
Calif does not claim an in-the-wild campaign, and The Hacker News found no reported attacks. What exists is a three-phone research demo and a Tencent mitigation. Treat scare numbers about a billion phones as the size of the address book, not as a body count.
The Times tags OpenAI Labs and Calif is an OpenAI Daybreak partner. Calif's post says the team worked with AI to find the bug and write the first RCE in about two days, then spent another week building the worm. That is assisted research, not an unattended model shipping malware.
Calif says declining ends that attempt. There is no published indicator that would let you tell a later successful try from a normal missed call. If you still run a July client, update. If you need certainty about a specific device, that evidence is not public.
xAI's Grok 4.20 card reports a 0.00 chat violation rate. The same PDF shows AgentHarm at 0.30. Production, a DSA case, and AB 316 already bind operators.
Adobe's APSB26-146 hotfix closes CVE-2026-75650, a CVSS 10.0 Magento RCE exploited from 4 Sept. Patching is not cleanup: hunt the implant and rotate credentials.
Manifold showed AI coding agents executing repo-named git helpers before any prompt. We reproduced the sink on Goose 1.41.0 and recorded the 1.44.0 fix.