AI-Developed Worm Exploits WeChat Vulnerability, Threatens Over a Billion Accounts
September 8, 2026
oecd:2026-09-08-b1bbView source ↗
What happened
Cybersecurity firm Calif used AI to develop WeWorm, a zero-click computer worm exploiting a WeChat vulnerability on Android and iOS. The worm could hijack accounts without user interaction and self-propagate via calls, threatening the privacy and security of over a billion users before Tencent patched the flaw.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
OECD AI Incidents Monitor
AI-Developed Worm Exploits WeChat Vulnerability, Threatens Over a Billion Accounts
2026-09-08