
AI-crafted WeChat worm hijacks accounts via ringless calls
Researchers at Calif say they used AI to develop WeWorm, a zero-click worm that hijacks a WeChat account during an incoming call by exploiting a memory-bug in WeChat’s calling stack, then automatically calls the victim’s contacts to spread. The attacker must be on the victim’s friend list, and once in, can read and send messages and perform actions as the owner. Tencent says the flaw was fixed and that no users were reported affected; no CVE or public advisory has been released. The team built the exploit in roughly two weeks after bug discovery, with a demo in August, and plans a full analysis for a conference. The case underscores AI-enabled attack risks and comes as EU cyber-resilience rules push for disclosure requirements.

