WeWorm: Zero-Click WeChat Worm
Summary
Calif reveals WeWorm, a zero-click worm that spreads via WeChat calls across Android and iOS, exploiting a memory corruption bug in WeChat's VoIP stack. The researchers demonstrate remote code execution and automatic propagation through a victim's trusted contacts, and note AI-assisted tooling aided discovery and exploit development. Tencent mitigated the issue; the article advocates industry collaboration to improve defense and awareness.