// hackerlogs
login+ register
Red TeamingLLM AppSecThreat BriefHigh

WeWorm Took WeChat Over While the Phone Rang. Tencent Closed It.

Calif demoed a zero-click WeChat account worm via an incoming call. Tencent blocked the exploit for all users by 28 August. There is no CVE and no reported outbreak.

The short answer

WeWorm is Calif's demo of a zero-click WeChat account takeover. An incoming call from a friend-list contact was enough; the victim did not have to answer. Calif says AI found the VoIP-stack memory bug and a first RCE in two days, then spent a week on a three-phone worm. Tencent mitigated the exploit for all users by 28 August.

Key takeaways

  • The demo is an unanswered WeChat call from a friend-list contact. Answering hears silence. Declining stops that attempt. The caller can try again later.
  • Calif showed three phones: a Pixel 10a took an iPhone 17e while it rang, then that iPhone took a second Pixel the same way. That is a lab worm, not a reported outbreak.
  • Tencent shipped Android 8.0.77 and iOS 8.0.76 on 21 August. Calif says a server-side block covered all users by 28 August. Tencent has not published an advisory or a CVE.
  • Calif is holding the VoIP-stack details for a conference. There is no IOC a user can search, and no way to tell whether a past missed call was this bug.
  • The Times headline says models built a worm. Calif's own clock is narrower: AI to first RCE in about two days, then a week of human work on the demo.

The New York Times headline is that AI models built a worm that could rapidly hack WeChat accounts. Calif is the firm that did the work, and their write-up is the document to file. The demo is a zero-click WeChat account takeover from an incoming call. The victim does not have to answer. Tencent, per Calif, has already blocked the exploit for every user. Nobody has published a CVE, and nobody has published an outbreak.

High Wormable account takeover on iOS and Android from a friend-list call, demonstrated in a lab, mitigated on Tencent's servers. High because of the trust graph, not because this is a confirmed campaign.

Three panels for WeWorm: a zero-click WeChat VoIP call that takes the account while the phone rings if the caller is on the friend list, a three-phone lab demo from Android to iOS to Android, and Tencent's 21 August client builds plus a 28 August server-side block with no public CVE.

What Calif actually showed#

Calif is a California security firm. Thai Duong, who ran Google's crypto work on BEAST, CRIME, and POODLE, is the chief. The research page published today names the demo WeWorm and calls it the first zero-click worm to spread through WeChat calls across iOS and Android.

The trigger is an incoming WeChat call. The target does not need to answer or touch the phone. If they do answer, they hear nothing and the exploit still lands. Declining ends that attempt. The attacker can call again later, including while the target is asleep.

The caller has to be on the target's friend list. That is a real gate, and it is a thin one once the first account falls. WeChat gives contacts extra privileges. A compromised friend is a trusted caller. Calif's demo is that hop: a Pixel 10a calls an iPhone 17e and takes WeChat while it is still ringing, then that iPhone calls a second Pixel 10a the same way.

What the exploit buys, on Calif's description, is the WeChat account: read and send messages, place calls, act as the user. WeChat is not only chat. Payments, official accounts, and mini programs sit in the same session. Calif says chaining this with other Android and iOS bugs they have reported can reach the device. Those other bugs are not in today's public write-up. Treat device-wide compromise as a claimed follow-on, not as the demo.

The class is memory corruption in WeChat's VoIP stack. Calif is holding the rest for a conference. We are not reconstructing the call. The operator fact is the trust graph plus an unanswered ringing path.

Two days, then a week, then a server block#

  1. Calif's engineering team becomes aware of a bug their AI work had already surfaced.
  2. Calif reports the bug to Tencent. Their WeChat accounts are banned the next day and restored on 29 July.
  3. First Android remote-code-execution exploit. iOS follows on 2 August.
  4. Polished three-phone worm demo across Android and iOS.
  5. Tencent ships Android 8.0.77 and iOS 8.0.76. The public notes say only that some known issues were fixed.
  6. Calif confirms the exploit is blocked on the server for all users.
  7. Tencent confirms to Calif that the issue can be used for remote command execution.
  8. Calif publishes. The Times and The Hacker News follow the same day.

Calif's marketing line is that AI found the bug and wrote the first RCE in about two days, and that the worm took one more week. Their own dates are longer than that slogan if you count calendar time from 23 July to 11 August. The Hacker News noted the gap. Keep both: the compressed working-time claim, and the disclosure clock Tencent actually ran.

The Times story, by Dustin Volz, is filed under US politics and tags OpenAI Labs, Tencent, and WeChat. Calif is an OpenAI Daybreak partner. The research post does not name a model. Do not brief this as an unattended GPT worm. Brief it as a red team that used AI to compress the find-and-exploit loop on a messaging VoIP stack, then spent a week turning two RCEs into a cross-platform hop.

Affected versions
ProductAffectedFixed in
WeChat AndroidUnpublished. Calif tested a Pixel 10a.8.0.77 (2026-08-21) plus server-side block by 28 Aug, per Calif
WeChat iOSUnpublished. Calif tested an iPhone 17e.8.0.76 (2026-08-21) plus server-side block by 28 Aug, per Calif
WeChat HarmonyOS / desktopNot stated by Calif or TencentNot stated

Tencent's own update log confirms the 21 August dates. The iOS note is "fixed some known issues." There is no security bulletin on Tencent's response site for this bug. The Hacker News checked. So did we: the versions exist; the advisory does not.

What to do#

If you run WeChat or Weixin on a phone you care about:

  1. Update. Android 8.0.77 or iOS 8.0.76 or later. Calif says the server block already covers older clients for this specific exploit. A current build is still the control you can verify.
  2. Do not treat a missed call as evidence either way. There is no published IOC. Calif has no user-visible tell, and Tencent has not offered one.
  3. If you operate a WeChat-connected agent, bot, or official-account webhook, this is not that class of bug. Separate 2026 issues in third-party WeChat agent frameworks are authentication mistakes on those products. WeWorm is Tencent's VoIP stack.
  4. If you do AI-assisted vulnerability research, file it. Calif's timeline is the useful part for a CISO: two days to a first RCE on a planet-scale messenger, a week to a worm demo, and a vendor that can still ship a server-side kill. The wrong lesson is to ban the models. The right one is to assume the next VoIP or call-setup surface is already in someone's queue.

Calif is right that WannaCry got out of a lab. They are also right that this write-up is a disclosure, not a drop. The missing artefacts are a CVE, an affected-version list, and a Tencent note that uses the word security. Until those exist, the operator action is update, and the briefing action is not to confuse a three-phone demo with a worm already in the wild.

Frequently asked

Do I have to update WeChat for the fix to apply?

Calif says Tencent blocked this exploit on the server for all users as of 28 August, so the block does not depend on you installing a build. Running a current client is still the safer default. Official logs list Android 8.0.77 and iOS 8.0.76 on 21 August. Neither firm has said whether HarmonyOS or desktop clients were in scope.

Was this used against real WeChat users?

Calif does not claim an in-the-wild campaign, and The Hacker News found no reported attacks. What exists is a three-phone research demo and a Tencent mitigation. Treat scare numbers about a billion phones as the size of the address book, not as a body count.

Did an OpenAI model write the worm by itself?

The Times tags OpenAI Labs and Calif is an OpenAI Daybreak partner. Calif's post says the team worked with AI to find the bug and write the first RCE in about two days, then spent another week building the worm. That is assisted research, not an unattended model shipping malware.

If I declined a WeChat call in July, was I hit?

Calif says declining ends that attempt. There is no published indicator that would let you tell a later successful try from a normal missed call. If you still run a July client, update. If you need certainty about a specific device, that evidence is not public.

Sources

  1. WeWorm Calif · 2026-09-08
  2. WeChat 8.0.76 for iOS Tencent Weixin · 2026-08-21
  3. Tencent Announces 2026 Second Quarter Results Tencent / PR Newswire · 2026-08-13

Related