I have for you this morning the disclosure of WeWorm, the zero-click attack against WeChat that reportedly used AI-assisted vulnerability discovery to move from vulnerability to working remote code execution in roughly two days. A pretty scary thought if I may say so.
Ted Miracco, CEO of Approov:
“The most interesting part of the WeChat exploit isn’t the bug; rather, it’s the timeline. It took only two days from the AI-discovered vulnerability to a working RCE, and one more week to a cross-platform worm. Work that used to take a competent team weeks or months. This speed to exploit collapses the assumption underlying patch-cycle security: that the window between bug discovery and weaponization gives defenders room to ship a fix and get it adopted.”
Jacob Krell, Senior Director, Secure AI Solutions & Cybersecurity at Suzu Labs:
“WeWorm fires while the phone is still ringing. The victim doesn’t answer, doesn’t tap anything, and it doesn’t matter. Once it takes over a WeChat account, it calls the victim’s contacts and repeats the cycle, spreading one friend list at a time. Declining the call blocks one attempt, but the attacker can retry while the victim sleeps.
“WeChat handles payments, government services, and business communications for 1.439 billion users. Compromising an account is closer to stealing someone’s digital identity than reading their texts.
“The economics shift is staggering in regards to AI vulnerability discovery. In 2019, NSO Group exploited CVE-2019-3568, a buffer overflow in WhatsApp’s Voice-over-IP (VoIP) stack, to deliver Pegasus spyware through the same missed-call pattern. That required $60 million a year in R&D and over 200 engineers from Israeli military intelligence. Calif built WeWorm with AI doing most of the heavy lifting in two days, their engineers providing the judgment on what to target and how to test safely.
“Same bug class, radically different cost structure. Any messaging app processing incoming calls before the user answers should assume their VoIP stack has bugs like this. If they haven’t run AI-assisted analysis against their own code yet, someone else’s AI will and find their bugs first.”
Expect more exploits like this because it is simply too cheap to not produce and exploit.
Related
This entry was posted on September 11, 2026 at 8:05 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
WeChat zero-click attack and AI-driven vulnerability discovery
I have for you this morning the disclosure of WeWorm, the zero-click attack against WeChat that reportedly used AI-assisted vulnerability discovery to move from vulnerability to working remote code execution in roughly two days. A pretty scary thought if I may say so.
Ted Miracco, CEO of Approov:
“The most interesting part of the WeChat exploit isn’t the bug; rather, it’s the timeline. It took only two days from the AI-discovered vulnerability to a working RCE, and one more week to a cross-platform worm. Work that used to take a competent team weeks or months. This speed to exploit collapses the assumption underlying patch-cycle security: that the window between bug discovery and weaponization gives defenders room to ship a fix and get it adopted.”
Jacob Krell, Senior Director, Secure AI Solutions & Cybersecurity at Suzu Labs:
“WeWorm fires while the phone is still ringing. The victim doesn’t answer, doesn’t tap anything, and it doesn’t matter. Once it takes over a WeChat account, it calls the victim’s contacts and repeats the cycle, spreading one friend list at a time. Declining the call blocks one attempt, but the attacker can retry while the victim sleeps.
“WeChat handles payments, government services, and business communications for 1.439 billion users. Compromising an account is closer to stealing someone’s digital identity than reading their texts.
“The economics shift is staggering in regards to AI vulnerability discovery. In 2019, NSO Group exploited CVE-2019-3568, a buffer overflow in WhatsApp’s Voice-over-IP (VoIP) stack, to deliver Pegasus spyware through the same missed-call pattern. That required $60 million a year in R&D and over 200 engineers from Israeli military intelligence. Calif built WeWorm with AI doing most of the heavy lifting in two days, their engineers providing the judgment on what to target and how to test safely.
“Same bug class, radically different cost structure. Any messaging app processing incoming calls before the user answers should assume their VoIP stack has bugs like this. If they haven’t run AI-assisted analysis against their own code yet, someone else’s AI will and find their bugs first.”
Expect more exploits like this because it is simply too cheap to not produce and exploit.
Share this:
Like this:
Related
This entry was posted on September 11, 2026 at 8:05 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.