WeWorm: first zero-click worm spreads via WeChat calls across iOS and Android
jedisct1 · x · 2026-09-09
Security firm Calif demoed WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android, covered by the New York Times.
- Merely calling a victim lets the attacker hijack their WeChat account while the phone is still ringing — no answer or interaction needed; even answering shows nothing.
- A three-phone demo (Pixel 10a → iPhone 17e → Pixel 10a) shows worm-style propagation: each victim becomes the next attacker.
- Exploitation takes seconds, enabling reading/sending messages, calls, and impersonation; chained with other reported bugs it can yield full device control.
- Declining the call blocks that attempt but attackers can retry. Potential exposure spans over a billion phones/accounts.
Related event: WeWorm: Zero-Click Worm Hijacks Accounts via WeChat Calls(3 posts)→
More from Safety
- micro1 moves to acquire Spirit's data, opens channel to reassure ex-employees — Exp_Mark · 2026-09-09
- Meta details Muse agent safety: sandboxed harness, Sentinel gatekeeper, user-held encryption — unixterminal · 2026-09-09
- Waqi: an MCP proxy that redacts PII from tool responses before the model sees them — AggressiveAnxiety481 · 2026-09-09
- The case for standard safety benchmarks as the alternative to per-model government approval — StrategicHarmony · 2026-09-09
- Anthropic Publishes Second Risk Report; Exec Downplays Current Models, Flags Recursive Self-Improvement — EvanHub · 2026-09-09
- Quantum AI is the most misused buzzword: it won't train GPT-6, but it can crack RSA — AryHHAry · 2026-09-09