Palo Alto security firm Calif on September 8 published a proof-of-concept it calls WeWorm: a worm that can take over a WeChat account from an incoming call the recipient does not have to answer, then use that account to call contacts and spread.

Calif says the victim does not need to pick up or touch the phone. Exploitation takes seconds and yields control of the WeChat account, including the ability to read and send messages and place calls. Answering does not stop it; the person who picks up hears silence and the exploit still runs. Declining the call ends that attempt, though the caller can try again later. The exploit requires the attacker to already be on the target’s WeChat friend list. Calif describes the bug as a memory-corruption issue in WeChat’s VoIP stack and is withholding the technical details for a later conference talk.

In the firm’s demo, a Pixel 10a placed a call to an iPhone 17e and took over that phone’s WeChat while it was still ringing. The compromised iPhone then called another Pixel 10a the same way.

Calif says that working with AI, its team found the bug and wrote the first remote-code-execution exploit in about two days, then built the worm in another week. A worm at this scale used to take a larger team months, the company said; AI can already do most of the work. Its own timeline is slightly longer than that slogan: the team learned of the bug on July 23, finished the first Android exploit on July 30, the iOS exploit on August 2, and a polished cross-platform demo on August 11.  Calif submitted the bug to Tencent on July 24. Tencent published WeChat Android 8.0.77 and iOS 8.0.76 on August 21 that mitigated the bug. Calif confirmed on August 28 that the exploit was also blocked on the server for all users. Tencent told the New York Times it had fixed the issue, had no reason to believe users were affected, and that customers did not need to update the app because of the server-side fix. There is no public report of the worm being used outside a lab.

WeChat is a payments-and-identity super app with more than a billion users, so a worm that spreads through missed calls among saved contacts would have been unusually consequential if it had been used in the wild. That is not the live story. The live story is a compressed offensive-research cycle: a small U.S. firm says AI helped it turn a VoIP memory bug into a cross-platform worm in days rather than months, then coordinated a fix with Tencent. That raises product-security questions for messaging platforms and a policy question about whether AI shortens the window defenders have before someone else finds the same class of bug.