Calif Research demonstrated WeWorm, the first zero-click worm that spreads through WeChat calls across iOS and Android without any user interaction. The team leveraged AI to discover the vulnerability and develop a remote code execution exploit in just two days, with the full worm built in about a week — a task that previously required larger teams over months.
Background
WeWorm was disclosed by Calif Research on September 10, 2026, highlighting how AI tools are dramatically accelerating the pace of vulnerability discovery and exploit development. This represents a significant shift in the security landscape, as AI-assisted attack development becomes increasingly accessible.
- Source
- Simon Willison
- Published
- Sep 10, 2026 at 08:56 AM
- Score
- 8.0 / 10