Calif built a zero-click WeChat worm that jumps between iOS and Android using AI
零点击微信蠕虫:人工智能将令黑客攻击更危险?
Calif researchers used a mix of AI models to build WeWorm in just over a week—a zero-click worm that spreads across iOS and Android through WeChat. An incoming call from a compromised contact is enough; the worm hijacks the account and then dials the victim's own contacts. Tencent confirmed the flaw and patched it, stating no users were affected. The attack exploits WeChat's trust model for saved contacts and, combined with other bugs, can give full phone control. Calif says human expertise was still needed end-to-end, but AI dramatically accelerated vulnerability discovery and exploit construction. The disclosure lands right after 100+ companies warned of an incoming wave of AI-powered cyberattacks.
Why it matters: NYT exclusive with Tencent confirmation and patch. AI-assisted vulnerability discovery moves from theory to real-world demo. Slight discount because the bug is already fixed with no known user impact, but the warning value clears the featured bar.