AI Computer Worm WeWorm Exposed Vulnerability in 1.4 Billion WeChat Accounts

Reviewed byNidhi Govil

6 Sources

Share

Palo Alto cybersecurity firm Calif used AI to develop WeWorm, a self-spreading computer worm that could hijack WeChat accounts through zero-click attacks in seconds. The vulnerability affected 1.4 billion users before Tencent patched the flaw, highlighting how AI accelerates both cyber threats and defense capabilities.

AI Computer Worm Developed in Days Threatens Billions

Cybersecurity firm Calif developed an AI computer worm called WeWorm that could have compromised over 1.4 billion WeChat accounts in a matter of hours

1

4

. The Palo Alto-based company used AI to discover a critical remote code execution vulnerability in WeChat's VoIP stack in just two days, then built the functional worm within one additional week

1

3

. This AI-developed computer worm represents a watershed moment in cybersecurity, demonstrating how artificial intelligence can compress months of traditional hacking work into days.

Source: NYT

Source: NYT

Zero-Click Attack Spreads Without User Interaction

WeWorm operates as a zero-click attack, requiring no user interaction to hijack WeChat accounts

4

5

. The AI-powered WeChat worm spreads through phone calls on the app, compromising accounts within seconds while the phone is still ringing

1

3

. Victims don't need to answer the call or interact with their phones at all for the attack to succeed. Only declining the call within seconds could prevent exploitation

5

. Once a single account falls victim, the self-spreading worm automatically targets the user's contact list, creating a chain reaction that could affect millions within hours

1

4

. The attack grants complete control over compromised accounts, allowing hackers to read and send messages, make calls, and act on the victim's behalf

1

.

Source: The Next Web

Source: The Next Web

Memory Corruption Flaw in WeChat VoIP Stack

The vulnerability exploited by WeWorm involved a memory corruption flaw in WeChat's voice-over-IP stack, which Calif described as an unconventional attack surface

1

5

. Calif reported the vulnerability to Tencent on July 24, and the company shipped fixes in Android version 8.0.77 and iOS version 8.0.76 on August 21

3

. Tencent confirmed it had no reason to believe the flaw compromised security or affected any users

3

4

. However, Tencent has published no public advisory, and Calif declined to confirm whether the underlying flaw itself was fixed or only the specific exploit was blocked

3

. The attack worked across both iOS and Android platforms, making it the first known computer worm capable of spreading across both operating systems without user interaction

4

.

AI Accelerates Both Threats and Defense

Calif's demonstration reveals how AI in cybersecurity fundamentally changes the timeline for developing sophisticated attacks. Thai Duong, Calif's chief executive, told The New York Times that building a worm at this scale "used to be the kind of thing that took a larger team months"

1

. The company used a combination of open-source and leading U.S. AI models, though it declined to specify which ones

4

. While AI discovered the vulnerability and helped build the exploit rapidly, human oversight remained essential. Duong noted his team had to "babysit the entire process" to get a working worm

3

. Calif also developed specialized skills to guide AI through the attack surfaces of messaging apps

3

. This pattern echoes recent AI-generated cyber threats: Google stopped the first AI-generated zero-day exploit in May, and an AI agent built a working macOS exploit in four hours in August

3

.

Source: VnExpress

Source: VnExpress

Geopolitical Implications for U.S.-China Relations

The WeWorm disclosure arrives as President Trump prepares to host Chinese leader Xi Jinping on September 24 in Washington, where AI safety is expected to be a key discussion point alongside trade

2

. Zhao Minghao, deputy director of the Center for American Studies at Fudan University in Shanghai, described the ability to take down WeChat as "a new kind of nuclear weapon" given the app's integration into Chinese national infrastructure

2

. The demonstration exposes China's digital vulnerabilities while simultaneously highlighting what Kyle Chan, a Brookings Institution fellow, called "the massive potential for other actors, nation-states or nonstate actors, to use AI to attack China's digital infrastructure"

2

. This creates what Zhao termed an "AI security dilemma" where defensive systems developed by one nation appear as offensive threats to the other

2

.

Industry Warnings and Call for Cooperation

Calif briefed White House officials before publicly disclosing the vulnerability

4

. The company urged both the U.S. and China to use AI models to strengthen defenses and fix vulnerabilities faster. "The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them," Calif stated

1

. The warning comes amid broader industry concerns about AI-driven cyber threats. OpenAI and over 100 major technology companies, including Calif, recently warned in an open letter that a wave of AI-enabled cyberattacks was coming

4

. Bill Gates called addressing AI safety risks "the world's top priority" in a New York Times interview

2

4

. Sam Altman, OpenAI's chief executive, told a G20 meeting that "some things are going to go very wrong with cybersecurity unless some people act quite urgently"

4

. Calif warned that the real danger lies in bad actors accessing similar frontier AI models: "All it takes is one lab accident or a person who grabs a half-finished version to unleash something like WeWorm into the world before anyone is ready"

1

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved