WeWorm: AI-built zero-click worm spreads via WeChat calls across iOS and Android
Simon Willison · rss · 2026-09-10
Calif Research has released a demo of WeWorm, reportedly the first zero-click worm to spread through WeChat calls across iOS and Android. The victim doesn't need to answer the call or interact with the phone at all — even answering yields no audible sound while the exploit succeeds.
Key facts:
- Working with AI, the team found the bug and wrote the first remote code execution (RCE) exploit in about two days, then spent one more week building the worm.
- A worm at this scale used to take a larger team months; the authors argue AI can already do most of the work, with humans contributing judgment on what to target and how to test safely.
A striking case study of AI collapsing the cost barrier for advanced attacks.
More from Safety
- Ex-DeepMind comms staffer: we were banned from discussing extinction risk — j_asminewang · 2026-09-10
- Researcher pushes for neutral third-party system to report dangerous AI model behavior — sierracatalina · 2026-09-10
- California signs first-in-the-nation AI audit laws SB 813 and AB 1405 — deanwball · 2026-09-10
- 'Occupy OpenAI' protest hits day 36 as activist hunger strike reaches day 8 — DavidSKrueger · 2026-09-10
- OpenAI's official blog: "The AI policy window is open. We need to act." — imadade · 2026-09-10
- Commenter warns AI race without international agreements 'will not end well for anybody' — Justin_Halford_ · 2026-09-10