A cybersecurity company used AI to discover and weaponize a remote code execution vulnerability in WeChat, building a self-replicating worm that could compromise over a billion accounts. The already-patched flaw highlights how dramatically AI can accelerate both offensive and defensive security work - compressing months of human effort into days.
How the WeWorm attack worked
Calif, a Palo Alto-based security firm, developed the worm after an AI model uncovered a memory corruption issue in WeChat's VoIP stack. The company described the attack surface as "unconventional." Exploitation took seconds and granted full control of a victim's account - letting an attacker read and send messages, make calls, and act on the user's behalf.
The worm could self-replicate, moving from one compromised account to another through friend lists. It affected both Android and iOS versions of WeChat, spreading via phone calls within the app. "The victim does not need to answer the call, or interact with their phone at all," Calif said. The firm posted a video demonstration of the attack, which it dubbed WeWorm.
AI compressed months of work into days
Tencent, WeChat's parent company, patched the vulnerability after Calif reported it in July. The flaw had existed for some time, meaning a human researcher could have found it eventually. The difference is speed. Calif's AI discovered the vulnerability in two days. "Building the worm took one more week. A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here," the company said.
Calif did not name the specific AI model used but said it partners with "frontier labs," suggesting access to a leading-edge system. The firm warned that a bad actor with similar tools - or even a leaked, unfinished model - could replicate the approach. "All it takes is one lab accident or a person who grabs a half-finished version to unleash something like WeWorm into the world before anyone is ready," Calif added.
The call for AI-driven defense
Rather than fueling calls for AI bans, Calif used the finding to argue for accelerated defensive adoption. The company urged industry and governments to deploy AI models to find and fix vulnerabilities before attackers do. "The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them. AI gives us an opportunity to find and fix vulnerabilities faster than ever, and we should work together to make the world safer for everyone," the company said.
For security teams, the implication is clear: the same speed that makes AI dangerous in the wrong hands makes it valuable for defenders. Professionals building detection and remediation pipelines can explore structured training like the AI for Cybersecurity Analysts Learning Path to integrate these techniques into their workflows.
Why this matters for IT and development teams
WeWorm is not a theoretical exercise. It demonstrates that memory corruption bugs in widely deployed software - the kind that have lingered for years - can now be found and weaponized in under two weeks with AI assistance. For developers and operations teams, the takeaway is that patch cycles measured in months are no longer adequate. Attack surface analysis, fuzzing, and code review processes that rely solely on manual effort will miss what an AI-augmented adversary can catch in days.
IT teams managing messaging platforms, VoIP infrastructure, or any consumer-facing application should treat AI-assisted vulnerability discovery as an operational reality, not a future threat. Resources like AI for IT & Development can help technical staff build the skills to audit and harden systems at the pace these tools now demand.
Your membership also unlocks: