Overview
- Calif researchers built a proof‑of‑concept worm called WeWorm that can take over a WeChat account when a user receives a ringing call without any interaction.
- The team says it found the VoIP memory‑corruption bug in July, built a remote‑code‑execution exploit by late July and demonstrated cross‑platform spread in mid‑August.
- Tencent released patched mobile builds on August 21 and applied a server‑side mitigation by August 28 that the company says has blocked the exploit for all users.
- The attack requires the caller to be in the victim’s WeChat contacts but can scale because a compromised contact can be used to reach more victims; once run the exploit gives full control of the WeChat account to the attacker.
- Calif withheld technical details while planning a conference presentation and warned that use of large language models sped exploit development, raising worry that AI will make similar attacks easier; checks found no public CVE or evidence of in‑the‑wild exploitation.