September 9, 2026
- WeWorm compromises a WeChat account via an incoming call the victim never picks up, then uses that account to call their contacts and continue spreading — across both iOS and Android. Calif.io says the team found the bug and wrote the first RCE exploit in about two days working with AI, reported it to Tencent, and the exploit is now mitigated for all users (Calif.io, The Hacker News). · Exploits & Vulnerability Research
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android