Security researchers at Calif have demonstrated WeWorm, a zero-click worm capable of hijacking WeChat accounts through incoming calls without requiring victims to answer, click a link or interact with their devices. The vulnerability affected WeChat’s VoIP stack across both iOS and Android.
The attack is particularly dangerous because it exploits trusted relationships. Once an account is compromised, the worm can use it to call the victim’s contacts, potentially turning every infected account into another attack point. Calif demonstrated the worm spreading across three phones within seconds.
AI played a significant role in accelerating the research. Calif says its team, working with AI, discovered the vulnerability and developed the first remote-code-execution exploit in about two days, followed by roughly another week to build the worm. This illustrates how AI could dramatically compress the time required to discover and weaponize vulnerabilities.
Importantly, this was a controlled security demonstration, not evidence of a widespread attack campaign. Calif responsibly disclosed the vulnerability to Tencent in July. WeChat updates addressing the issue were released in August, followed by server-side mitigation that Calif says blocked the exploit for users.
The larger warning goes beyond WeChat. Zero-click attacks combined with AI-assisted vulnerability discovery could redefine cybersecurity economics. Attackers may increasingly automate vulnerability research and exploit development, leaving defenders dramatically less time to respond. The security industry must therefore use AI equally aggressively for vulnerability discovery, patching and continuous threat detection—because the next cyberattack may begin without the victim clicking anything at all.





