# WeWorm Took WeChat Over While the Phone Rang. Tencent Closed It.

> WeWorm is Calif's demo of a zero-click WeChat account takeover. An incoming call from a friend-list contact was enough; the victim did not have to answer. Calif says AI found the VoIP-stack memory bug and a first RCE in two days, then spent a week on a three-phone worm. Tencent mitigated the exploit for all users by 28 August.

Source: https://hackerlogs.com/blog/weworm-wechat-zero-click
Published: 2026-09-08

## Key takeaways

- The demo is an unanswered WeChat call from a friend-list contact. Answering hears silence. Declining stops that attempt. The caller can try again later.
- Calif showed three phones: a Pixel 10a took an iPhone 17e while it rang, then that iPhone took a second Pixel the same way. That is a lab worm, not a reported outbreak.
- Tencent shipped Android 8.0.77 and iOS 8.0.76 on 21 August. Calif says a server-side block covered all users by 28 August. Tencent has not published an advisory or a CVE.
- Calif is holding the VoIP-stack details for a conference. There is no IOC a user can search, and no way to tell whether a past missed call was this bug.
- The Times headline says models built a worm. Calif's own clock is narrower: AI to first RCE in about two days, then a week of human work on the demo.

The [New York Times](https://www.nytimes.com/2026/09/08/us/politics/calif-ai-worm-wechat-hack.html) headline is that AI models built a worm that could rapidly hack WeChat accounts. [Calif](https://calif.io/research/weworm) is the firm that did the work, and their write-up is the document to file. The demo is a zero-click WeChat account takeover from an incoming call. The victim does not have to answer. Tencent, per Calif, has already blocked the exploit for every user. Nobody has published a CVE, and nobody has published an outbreak.

 Wormable account takeover on iOS and Android from a friend-list call, demonstrated in a lab, mitigated on Tencent's servers. High because of the trust graph, not because this is a confirmed campaign.

<img src="/weworm-wechat-zero-click.svg" alt="Three panels for WeWorm: a zero-click WeChat VoIP call that takes the account while the phone rings if the caller is on the friend list, a three-phone lab demo from Android to iOS to Android, and Tencent's 21 August client builds plus a 28 August server-side block with no public CVE." width="1200" height="675" />

## What Calif actually showed

Calif is a California security firm. Thai Duong, who ran Google's crypto work on BEAST, CRIME, and POODLE, is the chief. The [research page](https://calif.io/research/weworm) published today names the demo WeWorm and calls it the first zero-click worm to spread through WeChat calls across iOS and Android.

The trigger is an incoming WeChat call. The target does not need to answer or touch the phone. If they do answer, they hear nothing and the exploit still lands. Declining ends that attempt. The attacker can call again later, including while the target is asleep.

The caller has to be on the target's friend list. That is a real gate, and it is a thin one once the first account falls. WeChat gives contacts extra privileges. A compromised friend is a trusted caller. Calif's demo is that hop: a Pixel 10a calls an iPhone 17e and takes WeChat while it is still ringing, then that iPhone calls a second Pixel 10a the same way.

> Calif ran three phones in a lab. Tencent's second-quarter results put combined Weixin and WeChat monthly active users at 1.439 billion as of 30 June 2026. That is the size of the address book. It is not a victim count. Calif does not claim wild use, and The Hacker News found none.

What the exploit buys, on Calif's description, is the WeChat account: read and send messages, place calls, act as the user. WeChat is not only chat. Payments, official accounts, and mini programs sit in the same session. Calif says chaining this with other Android and iOS bugs they have reported can reach the device. Those other bugs are not in today's public write-up. Treat device-wide compromise as a claimed follow-on, not as the demo.

The class is memory corruption in WeChat's VoIP stack. Calif is holding the rest for a conference. We are not reconstructing the call. The operator fact is the trust graph plus an unanswered ringing path.

## Two days, then a week, then a server block

Calif's marketing line is that AI found the bug and wrote the first RCE in about two days, and that the worm took one more week. Their own dates are longer than that slogan if you count calendar time from 23 July to 11 August. The Hacker News noted the gap. Keep both: the compressed working-time claim, and the disclosure clock Tencent actually ran.

The Times story, by Dustin Volz, is filed under US politics and tags OpenAI Labs, Tencent, and WeChat. Calif is an OpenAI Daybreak partner. The research post does not name a model. Do not brief this as an unattended GPT worm. Brief it as a red team that used AI to compress the find-and-exploit loop on a messaging VoIP stack, then spent a week turning two RCEs into a cross-platform hop.

Tencent's own [update log](https://weixin.qq.com/updates?platform=ios&version=8.0.76) confirms the 21 August dates. The iOS note is "fixed some known issues." There is no security bulletin on Tencent's response site for this bug. The Hacker News checked. So did we: the versions exist; the advisory does not.

## What to do

If you run WeChat or Weixin on a phone you care about:

1. Update. Android 8.0.77 or iOS 8.0.76 or later. Calif says the server block already covers older clients for this specific exploit. A current build is still the control you can verify.
2. Do not treat a missed call as evidence either way. There is no published IOC. Calif has no user-visible tell, and Tencent has not offered one.
3. If you operate a WeChat-connected agent, bot, or official-account webhook, this is not that class of bug. Separate 2026 issues in third-party WeChat agent frameworks are authentication mistakes on those products. WeWorm is Tencent's VoIP stack.
4. If you do AI-assisted vulnerability research, file it. Calif's timeline is the useful part for a CISO: two days to a first RCE on a planet-scale messenger, a week to a worm demo, and a vendor that can still ship a server-side kill. The wrong lesson is to ban the models. The right one is to assume the next VoIP or call-setup surface is already in someone's queue.

Calif is right that WannaCry got out of a lab. They are also right that this write-up is a disclosure, not a drop. The missing artefacts are a CVE, an affected-version list, and a Tencent note that uses the word security. Until those exist, the operator action is update, and the briefing action is not to confuse a three-phone demo with a worm already in the wild.

## Sources

- [WeWorm](https://calif.io/research/weworm) (2026-09-08)
- [WeWorm: The first zero-click worm to spread through WeChat calls](https://blog.calif.io/p/weworm) (2026-09-08)
- [A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts](https://www.nytimes.com/2026/09/08/us/politics/calif-ai-worm-wechat-hack.html) (2026-09-08)
- [WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls](https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html) (2026-09-08)
- [WeChat 8.0.76 for iOS](https://weixin.qq.com/updates?platform=ios&version=8.0.76) (2026-08-21)
- [WeChat update log (Android 8.0.77, iOS 8.0.76)](https://weixin.qq.com/updates) (2026-08-21)
- [Tencent Announces 2026 Second Quarter Results](https://www.prnewswire.com/apac/news-releases/tencent-announces-2026-second-quarter-results-302849608.html) (2026-08-13)
