Calif Research demos WeWorm, a zero-click WeChat worm built with AI

Calif Research has announced a demo of WeWorm, which it describes as the first zero-click worm to spread through WeChat calls across iOS and Android. The text appeared as a quotation post on Simon Willison's blog, dated 10 September 2026. By the group's account the attack needs nothing at all from the person being targeted: "The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds."

The group's own emphasis falls on the timeline. Working with AI, the team says it found the bug and wrote the first remote code execution exploit in about two days. Building the worm on top of that took one more week. Calif Research sets that against what it says the same job used to cost: "A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely." The split it describes leaves the humans with a narrow slice: choosing the target and working out how to test it safely.

What the published text leaves out matters as much as what it says. The passage is an excerpt whose technical middle is elided with "[...]", and no description is given of what the underlying WeChat bug actually is. No AI tool, model or vendor is named; the text says only "working with AI". There is no CVE identifier, no severity score and no count of affected users. Nothing is said about whether Tencent has been notified, has responded, or has patched anything, and no responsible-disclosure timeline is given. Nothing states whether WeWorm's code or the exploit will be published or kept as a private demo. No individual on the team is named, and the two durations are given without calendar dates.

Key facts

  • Calif Research announced a demo of WeWorm on 10 September 2026, calling it the first zero-click worm to spread through WeChat calls across iOS and Android.
  • By the group's description the target does nothing: "The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds."
  • Working with AI, the team says it found the bug and wrote the first remote code execution exploit in about two days, then took one more week to build the worm.
  • Calif Research says a worm at this scale "used to be the kind of thing that took a larger team months" and that "AI can already do most of the work here", with the team supplying judgment on what to target and how to test safely.
  • The published text carries no description of the underlying WeChat bug, names no AI tool or model, gives no CVE or severity score, and says nothing about whether Tencent was notified or anything was patched.

Why it matters

An exploit that needs no action from the target sits at the top end of offensive capability, and Calif Research claims one that spreads by itself through WeChat calls on both iOS and Android, a single vector working across two different mobile platforms. The group's own framing is the point of the announcement. What it says used to take a larger team months took its team about two days to find and exploit, plus one more week to turn into a worm. If that account holds, the binding constraint on building this class of attack has moved from specialist team-months to a decision about what to point the tooling at. Calif Research puts it directly: AI can already do most of the work here, and the team supplied the judgment about targeting and safe testing. The demo is presented as evidence of that shift rather than as a technical account of the bug, and the source text carries no detail with which to argue the point either way.

Who it affects

WeChat users on iOS and Android are the population the claim covers, and by the group's description they have no behavioural defence: no call to decline, no link to avoid, no prompt to ignore. Answering changes nothing either, since the victim hears nothing and the exploit still succeeds. On the vendor side the source is silent. It says nothing about whether Tencent was notified, whether it responded, or whether anything has been patched, so the state of the fix is simply unknown from this text. The second audience is the security field itself: red teams, vulnerability researchers and anyone estimating how long a capability of this class now takes to build have a public, self-reported number to work from.

How to use it

There is nothing operational here. The announcement is a demo notice, not a write-up: no description of the bug, no CVE identifier, no severity score, no indicators, and no statement about whether the code or the exploit will be released or kept private. There is no patch to install or mitigation to apply either, because the text says nothing about Tencent having been notified or having responded. What the material does give you is a dated, attributable claim about cost: about two days from bug to remote code execution exploit, one more week to the worm, set against a stated prior baseline of months for a larger team. That is the figure worth carrying into a threat model or a budget conversation, with the caveat that it comes from the people making the claim. The quoted passage is short enough to cite in full.

How solid is it

Every fact here comes from Calif Research's own announcement, quoted on Simon Willison's blog on 10 September 2026. The source contains no independent confirmation of any of it, and no third party is cited as having reproduced or reviewed the work. The passage is an excerpt with elisions marked "[...]", and the elided part is exactly where a description of the bug would sit; the text as published gives none. No AI tool, model or vendor is named, so "working with AI" cannot be checked against any particular system. No individual person is named on the team, only the organisation and "our team". The two durations, about two days and one more week, come without calendar dates. There is no CVE identifier, no severity score and no count of affected users. The word "first", in "the first zero-click worm to spread through WeChat calls", is the group's own characterisation.

Risks and caveats

This is a capability claim published by the group that made it, in the announcement of its own demo, and a self-reported timeline from an organisation with an interest in the result deserves the usual discount. "Working with AI" is carrying weight without definition: the phrase spans everything from code completion to automated bug hunting, and the source does not say which. The comparison to months for a larger team is offered without a reference case to check it against. On disclosure the text is silent where silence matters most. Nothing on whether Tencent was told, nothing on a fix, nothing on whether the worm or the exploit stays private. A demo of a self-spreading mobile worm announced without any of that is a different object from a coordinated disclosure, and the source gives no basis for judging which one this is. There is also a general claim buried in the specific one: what Calif Research describes is a change in the cost of the work rather than anything peculiar to this bug, so on its own terms the same compression would apply to other targets.

“A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely.”

— Calif Research, WeWorm