A cybersecurity firm based in California has developed a worm capable of taking control of WeChat accounts without any interaction from the user, according to recent reports. This type of attack, known as a zero-click exploit, occurs when a phone receives a call, allowing the attacker to gain control of the WeChat account before the user even answers the call. The vulnerability lies in WeChat's VoIP stack, a part of the app that handles audio and video calls. The exploit uses a memory corruption bug, which allows attackers to run code on the target device when improperly formatted data is sent during the call setup. The worm, named WeWorm by the researchers, was developed using artificial intelligence, which greatly sped up the process of identifying and exploiting the vulnerability. The vulnerability was discovered in mid-July 2026, and the research team notified Tencent, the parent company of WeChat, just 10 days later. Tencent released updates for iOS and Android on August 21, 2026, and confirmed by the end of August that the exploit had been neutralized on the server side, without needing any action from users. The California team built a working exploit for Android within a week of finding the vulnerability and for iOS by the end of July and early August. The full worm was operational by August 11 and could spread from account to account without human involvement. The researchers used several artificial intelligence models to speed up each part of the process, but they personally selected the targets and verified each result from the AI before integrating them into the exploit. The worm takes over the victim’s contact list and automatically redials, spreading the infection from person to person. The only way to prevent the account from being compromised is to immediately reject the call. Answering or letting it ring results in the account being taken over. Once compromised, the worm allows the attacker to read and send messages, make calls, and act on behalf of the victim. Combined with other Android and iOS vulnerabilities, this could allow complete control of the device. Calif claims to have followed responsible disclosure practices and has no evidence that the vulnerability had been used in the real world before its disclosure. Tencent confirmed that the vulnerability had been fixed on August 28, both in the app and on its servers, before any public announcement. However, the company stated it has not found any evidence that a real account had been compromised. The incident has raised concerns among former American intelligence specialists, who worry about an escalation in cyber threats. Ryan Fedasiuk, an AI policy researcher, called the WeChat worm an extremely serious incident, linking it to the Superintelligence Strategy report, which suggests a mutual deterrence approach in artificial intelligence. Former NSA chief data scientist Vinh Nguyen described this worm as one of the most alarming cyberattacks he had ever encountered, noting that it could affect hundreds of millions of devices within a few hours.