Full Report
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
Analysis Summary
# Vulnerability: WeWorm Zero-Click VoIP Remote Code Execution (RCE)
## CVE Details
- **CVE ID:** Not yet assigned (Research published by Calif)
- **CVSS Score:** N/A (Estimated Critical/9.0+)
- **CWE:** CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) / Memory Corruption
## Affected Systems
- **Products:** Tencent WeChat
- **Versions:** All versions prior to the August 21, 2026 patch
- **Configurations:** Default installations on both **iOS** and **Android** platforms.
## Vulnerability Description
The vulnerability is a memory corruption flaw residing within WeChat’s VoIP (Voice over IP) stack. The flaw allows for "zero-click" exploitation, meaning the victim does not need to answer the call or interact with the device to trigger the bug. By sending a specially crafted VoIP packet during the initiation of a call, an attacker can trigger memory corruption, leading to Remote Code Execution (RCE) within the context of the WeChat application.
## Exploitation
- **Status:** PoC developed by researchers; patched by vendor. No confirmed "in-the-wild" exploitation by malicious actors reported yet, though researchers highlight that AI-assisted development makes this highly accessible.
- **Complexity:** High (requires advanced exploit chaining for full device takeover), but "Medium" for account-level takeover as AI tools were used to automate the RCE development.
- **Attack Vector:** Network (VoIP Call)
- **Prerequisites:** The attacker must be on the victim's "Friends" list (Trusted Contact).
## Impact
- **Confidentiality:** High (Ability to read all messages and access account data)
- **Integrity:** High (Ability to send messages and make calls as the victim)
- **Availability:** High (Potential to crash the application or take over account access)
- **Note:** If chained with OS-level vulnerabilities (e.g., "OEMpocalypse"), the impact extends to **Full Device Compromise**.
## Remediation
### Patches
- **Tencent WeChat:** Fixes were deployed by Tencent on **August 21, 2026**. Users should ensure they are running the latest version of WeChat from the official iOS App Store or Google Play Store.
### Workarounds
- **Trusted Contacts Only:** Since the exploit requires the attacker to be a "Friend," users should audit their friends list and remove unknown or untrusted accounts.
- **Manual Decline:** In the research demo, manually declining the call (hanging up immediately) prevented the infection, whereas letting it ring or answering it allowed the exploit to succeed.
## Detection
- **Indicators of Compromise:**
- Unexplained incoming VoIP calls that terminate quickly.
- Messages sent from the account that the user did not author.
- VoIP calls initiated by the account to other contacts without user intervention.
- **Detection methods and tools:** Currently, detection relies on behavioral analysis of the application (e.g., monitoring for unauthorized outgoing calls or API calls to message databases).
## References
- **Calif Research:** hxxps[://]calif[.]io/research/weworm
- **OEMpocalypse Reference:** hxxps[://]calif[.]io/research/oempocalypse
- **Researcher Social Media:** hxxps[://]x[.]com/ryanfedasiuk/status/2097464170405077367?s=51