LIVE
+++ AI Found the Zero-Click Flaw in WeChat Calling +++ Intel Says It Is Already Making Chips on High-NA EUV +++ OpenAI Says Cheaper AI Expands What Work Is Possible +++ Samsung Opens AI Chip Packaging Center in Yokohama +++ Philippines bets $34.4bn on becoming an AI hub +++ OpenAI Expands Its Journalism Support Programs ++++++ AI Found the Zero-Click Flaw in WeChat Calling +++ Intel Says It Is Already Making Chips on High-NA EUV +++ OpenAI Says Cheaper AI Expands What Work Is Possible +++ Samsung Opens AI Chip Packaging Center in Yokohama +++ Philippines bets $34.4bn on becoming an AI hub +++ OpenAI Expands Its Journalism Support Programs +++
All news ›
AI IN LIFE AI IN LIFENEWS
DAILY
DE EN
SECURITY

AI Found the Zero-Click Flaw in WeChat Calling

A memory bug in WeChat's voice-calling stack let an AI-built worm hop from contact to contact — no tap required. Tencent shipped the fix on August 21.

AI Found the Zero-Click Flaw in WeChat Calling

Symbolic image: phones clamped in a test rig light up with an incoming call while a hand reattaches a cable.

Security firm Calif's AI system found a memory bug in WeChat's VoIP architecture that would have let a worm jump from contact to contact with no user action at all, and Tencent closed it on August 21, 2026.

At a glance

  • Affected: WeChat's VoIP architecture on iOS and Android — a memory bug in the calling stack.
  • Reported to Tencent on July 24, 2026; iOS and Android updates landed on August 21, 2026.
  • First working exploit in two days; the finished WeWorm took one more week.
  • Over one billion WeChat accounts were potentially exposed; per t3n, Tencent knows of no attacks.
  • WeChat suspended Calif's own accounts after the report, then reversed the suspension.

An AI system at the California security firm Calif found a memory bug in WeChat's voice-calling architecture and turned it into a zero-click worm. Tencent has since patched it on both iOS and Android.

A call you never had to answer

The entry point was an incoming VoIP call inside WeChat. The target did not have to pick up, because the compromise happened on the ring itself. Only declining the call fast enough might have stopped it, according to t3n's account.

From there the worm reached the victim's stored contacts, which carry elevated permissions inside the app, and dialed them in turn. Because each call arrived from a familiar name, the spread rate compounded with every account taken. The same code worked across Android and iOS.

Two days to a working exploit

The speed is the story here, more than the bug itself. Once the AI had identified the weakness, a first working exploit existed two days later, and the finished worm took one more week. Calif chief executive Thai Duong told t3n that without those tools the job would have needed a larger team and several months.

Neither report names the model or the vendor behind Calif's system, and neither mentions a bug bounty payout.

Report, lockout, patch

Calif sent the report to Tencent on July 24, 2026. WeChat then suspended the researchers' own accounts, a lockout that was later reversed. Updates for both mobile platforms went out on August 21, 2026.

Anyone running a current build is covered. Taking over the whole phone, rather than the account, would have required further vulnerabilities that this bug did not supply on its own.

The defensive read

Stories like this usually get filed under the heading of AI helping attackers. Calif argues the opposite direction: what changed is that flaws now get found and closed quickly. One case is not a measurement, and neither report offers comparative data to support the broader claim.

Whether anyone else had spotted the bug before the patch is unclear. Tencent says it knows of no exploitation, per t3n, and that statement has not been independently confirmed.

◈ AI-GENERATED REPORT · SOURCES LINKED

FAQ

Is WeChat safe now?

On current builds, yes. Tencent shipped iOS and Android updates on August 21, 2026 that close the memory bug in the VoIP layer.

Did the victim have to answer the call?

No. The exploit ran on the incoming call itself; per t3n, only declining it very quickly might have prevented it.

Which AI model found the WeChat bug?

That has not been disclosed. Both reports refer only to an AI system at Calif, without naming a model or a vendor.