WeWorm: first zero-click worm spreading via WeChat calls across iOS and Android
emollick · x · 2026-09-09
Calif Research has demoed WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android (covered by the NYT).
- Attackers only need to place a call — no answer or interaction required — hijacking the WeChat account within seconds, even while the phone is still ringing
- A three-phone chained demo: a Pixel 10a calls an iPhone 17e and takes over its WeChat, then the compromised iPhone attacks the next Pixel — victims become attackers
- Full account control: reading/sending messages, calls, impersonation; chained with other reported bugs it could yield complete device control
- Potential exposure exceeds a billion phones/accounts. Ethan Mollick adds that however worried companies are about cybersecurity, it's not enough — and the Hugging Face Incident shows you don't even need bad actors
Related event: WeWorm: Zero-Click Worm Hijacks Accounts via WeChat Calls(3 posts)→
More from Fun
- Biologist has GPT-6 Astra design a custom pipette from scratch for 3D printing — DeryaTR_ · 2026-09-09
- Why you should catch up on Michael Levin's takes on intelligence — cephaloform · 2026-09-09
- AI circle meme: asking Sam Altman to fund the cat-ears peptide next — QuintinPope5 · 2026-09-09
- Satirical 'Torment Sphere' engineer resigns, citing failed alignment at EvilCorp — Elijah_Meeks · 2026-09-09
- Devs turn a retired Meta Portal into a baby-care voice logger using gpt-realtime API — SIGKITTEN · 2026-09-09
- Everyone's still warming up to one agent; OpenAI is unleashing 10,000 on math nerds — msg · 2026-09-09