WeChat worm could pwn a friend before they even answered the call
- ID
- 22740
- Status
- summarized
- Published
- 09 Sep 2026, 8:45 PM
- Fetched
- 09 Sep 2026, 8:47 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/09/wechat-worm-could-pwn-a-friend-before-they-even-answered-the-call/5295234
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 6.0
- Created
- 09 Sep 2026, 8:48 PM
- Tags
- Audience
- developersai_ml_learnerssaas_startup_founders
What happened
Security researchers at Calif discovered a zero-click worm in WeChat's VoIP stack that could hijack a user's account before they answered a call, then auto-call trusted contacts to spread. Tencent patched the flaw on August 21, but Calif withheld full exploit details. Calif reported using AI to find the vulnerability and develop a working RCE exploit in approximately two days.
Why it matters
WeChat is widely used across Malaysia and SEA for business and personal communication; if your team or customers use it, confirm devices have updated to versions with Tencent's August 21 patch. The AI-assisted exploit development timeline (~2 days from bug discovery to RCE) is a concrete signal that AI-assisted vulnerability research is compressing the window between flaw and weaponization, which should factor into how fast you patch and how seriously you treat dependency and client-app update cycles.
Discussion angle
AI compressed bug-to-exploit to roughly two days here — what does that mean for patch SLAs in your own stack, and does it change how you prioritize security tooling vs. manual review?