Tech Made Simple

Hot Topics: IFA 2026All Roku Players Compared | Best iPad Keyboard Cases | The Best Open Ear Earbuds of 2026

We may earn commissions when you buy from links on our site. Why you can trust us.

author photo

AI created worm could have hacked millions of people in a few hours

by Suzanne Kantra on September 08, 2026

Concept image showing how WeWorm infects other phones through WeChat calls.

Suzanne Kantra/Techlicious generated by ChatGPT

Security researchers say they used artificial intelligence to build a self-spreading exploit for WeChat that could have hijacked accounts on iPhone and Android without the victim tapping, answering, or even touching their phone. Tencent, which owns WeChat, has already patched the flaw.

The exploit, which the researchers named WeWorm, came from Calif, an offensive-security firm led by Thai Duong, a researcher known for prior work at Google's security team. Calif describes WeWorm as the first zero-click worm to spread through WeChat calls, meaning a victim's account could be taken over while their phone was still ringing, before they ever picked up.

The bug lived in WeChat's VoIP call-handling code, the software that manages voice and video calls inside the app. According to Calif's report, an incoming WeChat call from an attacker could trigger memory corruption in that code, letting the attacker hijack the account mid-ring. Once in, the attacker could read and send messages, place calls, and act as the victim, including placing the same kind of call to the victim's own contacts. That created the potential for exponential growth as the exploit hopped from one hijacked account to the next contact on its list.

Calif says its team built the entire attack, from finding the bug to writing working code that could take full control of the app remotely, known in the security industry as a remote-code-execution exploit, in about two days, crediting artificial intelligence for the pace. "Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days," the company wrote, adding that its researchers still supplied the judgment calls on what to target and how to test the exploit safely.

The attack was tested against an iPhone 17e and a Pixel 10a, and any device running WeChat versions older than iOS 8.0.76 or Android 8.0.77 was vulnerable. Given how widely WeChat is used across China and Chinese-speaking communities worldwide, Calif estimates the flaw could have been used to compromise more than a billion phones or accounts had it been released in the wild.

Calif notified Tencent of the vulnerability in July and Tencent shipped a fix in August with its iOS 8.0.76 and Android 8.0.77 versions. Server-side protections were in place by August 28.

"The easy reaction is to blame AI and try to curtail its further development. We think that is the wrong lesson.", Calif notes. "The vulnerabilities are already out there. What AI changed is that we can find and fix them fast. We believe there are more good guys than bad guys, and if they're paying attention, AI gives the good guys the upper hand."

Let's hope they're right.

Read nextThe best antivirus apps for Android in 2026


Topics

News, Phones and Mobile, Mobile Apps, Blog, Privacy


Discussion loading

Home | About | Meet the Team | Contact Us
Media Kit | Newsletter Sponsorships | Licensing & Permissions
Accessibility Statement
Terms of Use | Privacy & Cookie Policy

Techlicious participates in affiliate programs, including the Amazon Services LLC Associates Program, which provide a small commission from some, but not all, of the "click-thru to buy" links contained in our articles. These click-thru links are determined after the article has been written, based on price and product availability — the commissions do not impact our choice of recommended product, nor the price you pay. When you use these links, you help support our ongoing editorial mission to provide you with the best product recommendations.

© Techlicious LLC.