Security researchers demonstrated WeWorm, a zero-click worm capable of spreading between iOS and Android devices through WeChat calls without requiring victims to answer or interact with their phones. The exploit targets a memory corruption issue in the app’s VoIP stack, allowing a compromised account to call trusted contacts and continue spreading. Researchers also used AI to help discover the vulnerability and develop the exploit, highlighting how advanced attack development could become faster and more accessible. The vulnerability has since been mitigated, but the research demonstrates the growing risk posed by zero-click attack surfaces in mobile messaging applications.
Read the full report here.
© 2026 Zimperium. All Rights Reserved. Privacy Settings Modern Slavery Act Statement