In July 2026, the Calif research team used AI to discover a WeChat VoIP memory corruption vulnerability within two days and built WeWorm—a worm that spreads automatically through calls—within a week.
The Facts
According to the demonstration records released by Calif, the attack flow begins with a call placed from an Android Pixel 10a device to an iPhone 17e. Remote code execution is completed during the ringing phase, taking over the WeChat account. The iPhone then places another call to a second Android Pixel 10a, achieving chain infection. The entire process requires no answer or any user interaction; even if victims pick up, they hear nothing unusual. Calif said the vulnerability requires the attacker to already be on the victim's friend list, but indirect access can be achieved by first compromising the account of one friend.
The disclosure timeline shows that the AI discovered the vulnerability in July 2026, the engineering team confirmed it on July 23, and it was submitted to Tencent on July 24. The related accounts were suspended from July 25 to 28 and later restored. The iOS RCE exploit was completed on August 2, and a cross-platform worm demonstration was completed on August 11. Tencent released Android 8.0.77 and iOS 8.0.76 on August 21 and confirmed on August 28 that server-side measures had mitigated the risk for all users. Calif shared the full analysis and exploit code on September 3 and published the article on September 8.
Mechanism Breakdown
The core of WeWorm is a memory corruption vulnerability in the VoIP stack that allows code injection during the call establishment phase and control over WeChat account functions, including reading and sending messages and initiating new calls. The demonstration shows the exploit takes only seconds to gain full control of an account. Combined with other reported Android and iOS vulnerabilities, it could further achieve device-level control. Calif noted that messaging apps grant friend lists a higher level of trust; once one contact is compromised, that trust relationship instead becomes a propagation path.
The development process shows that AI handled most of the code writing and vulnerability identification, while the team provided target selection and security testing judgment. In the past, worms of comparable scale typically required a larger team working for months, whereas this time it took only about nine days from vulnerability discovery to a working worm prototype.
Industry Impact
The incident directly involves Tencent's WeChat service, which covers users in China and Chinese communities worldwide. Tencent completed server-side fixes quickly after receiving the report, and there is no evidence of users being harmed. Other messaging applications similarly face unconventional attack surfaces such as VoIP. Calif said it is working with other developers to reduce attack surfaces, and such efforts may require joint participation from platform operators.
This case makes concrete AI's role in exploit development: the cycle from discovery to weaponization has been drastically shortened, lowering the threshold for tasks that previously required highly skilled teams. Historical precedents such as WannaCry show that leaks of early-stage tools can lead to large-scale impact; this disclosure is intended to alert all parties to the capability diffusion brought by AI.
Strategic Assessment
[Analysis] By compressing the development cycle of advanced attack chains from months to days, AI means defenders must accelerate their own vulnerability discovery and patching at the same pace, otherwise the window of risk for ordinary users may widen. Calif stressed that the vulnerability itself had long existed; AI can be used for both attack and defense, and the key is whether more well-intentioned participants can master and apply these capabilities first. The incident calls for the US, China, and other governments, along with the private sector, to collaborate in AI security to reduce potential cascading risks around the world.
© 2026 Winzheng.com 赢政天下 | 转载请注明来源并附原文链接