# Calif demo shows zero-click WeChat worm; Tencent says exploit mitigated

_Saturday, September 12, 2026 at 1:49 AM EDT · Security, AI · Latest · Tier 2 — Notable_

Security firm Calif published a demo of WeWorm, which it describes as the first zero-click worm spreading through WeChat calls on iOS and Android.

In the demo, a call from a compromised contact hijacked a victim's WeChat account while the phone was still ringing, and the compromised device then called the next target. Calif says the bug was a memory corruption issue in WeChat's VoIP stack, that it reported the flaw to Tencent on July 24, and that Tencent mitigated the exploit server-side for all users by August 28.

Calif says it built the exploit with AI assistance and is withholding technical details until a conference presentation.

## Sources

- [calif.io](https://calif.io/research/weworm)

---
Canonical: https://techandbusiness.org/newswire/Hc2pLa86KoalG5pkz9cKMd
Retrieved: 2026-09-12T09:25:07.728Z
Publisher: Tech & Business (techandbusiness.org)
