AI-Powered WeChat Worm Can Hijack Mobile Devices via Incoming Calls
Share
Researchers have developed a zero-click worm capable of hijacking Android and iOS devices through simple incoming WeChat calls. The tool, dubbed WeWorm, allows an attacker to gain control over a targeted WeChat account without any interaction from the victim.
Developed by the cybersecurity startup Calif, the worm exploits a remote code execution (RCE) vulnerability within WeChat’s voice-over-IP (VoIP) stack. The flaw is a memory corruption issue that relies on the elevated privileges granted to trusted contacts when communicating with other users on the platform.
AI-Accelerated Exploit Development
The researchers utilised a combination of large language models (LLMs), including both open-weight and closed-source frontier models, to identify the vulnerability. This use of artificial intelligence significantly accelerated the development process; the team reported that they developed exploits for the vulnerable apps in just two days and integrated them into the WeWorm tool within a week.
“AI can already do most of the work here,” the Calif researchers stated, noting that their primary role involved providing the strategic judgment required to target and test the vulnerability safely.
Impact and Attack Vector
WeWorm provides an attacker with extensive control over the victim’s WeChat account, enabling them to read and send messages, make calls, and perform actions on the user’s behalf. A critical aspect of the exploit is that the victim does not need to answer the incoming call for the attack to succeed. Even if the user answers the call, they will hear nothing, and the exploitation process will continue.
While the exploit currently requires the attacker to be on the victim’s friend list, researchers noted this is not a significant barrier. An attacker can compromise a single contact to gain access to the target’s social circle. Furthermore, if WeWorm is chained with other mobile operating system vulnerabilities, it can lead to full control of the entire device.
Mitigation and Patches
Tencent, the developer of WeChat, has confirmed that the vulnerability could allow for remote command execution. The company has since released patched versions of the application to address the flaw.
Users should immediately update to the following versions to secure their devices:
- Android: WeChat version 8.0.77 or higher
- iOS: WeChat version 8.0.76 or higher




Leave a Reply