WeWorm: Zero-Click WeChat Call Worm Hijacks Accounts Across iOS and Android
jedisct1 · x · 2026-09-08
Calif Research published WeWorm, the first zero-click worm spreading through WeChat calls across iOS and Android: a victim's account is fully compromised within seconds of an unanswered call, then used to attack the next contact. Reported to Tencent and now mitigated for all users; covered by the NYT. The team argues AI can help find and fix such bugs faster.
More from Safety
- ECCV 2026 Workshop on Privacy-Preserving Visual Localization Features Brachmann, Pollefeys Talks — ducha_aiki · 2026-09-08
- Xbow's AI agent pops the calculator in a browser, netting a $250k bug bounty — moyix · 2026-09-08
- Physicist flags the most worrying part of the OpenAI/Hugging Face incident — skdh · 2026-09-08
- Google GTIG: threat actors now run agentic AI attacks, harvesting credentials in under 6 hours — ChuckDBrooks · 2026-09-08
- Secretive DHS 'Predictive Policing' Unit Analyzes Americans' Financial Habits, Stops Them — abraham · 2026-09-08
- Report: OpenAI Stole Mathematicians' Private Research from Their Own Codex Chats — nreece · 2026-09-08