Quoting Calif Research
· Source: Simon Willison
Calif Research has released a demonstration of “WeWorm,” a worm that spreads via WeChat calls on iOS and Android devices without requiring the victim to answer or interact with the phone. The malware activates even if the user responds, because the call produces no sound and the malicious code runs regardless. According to the team, the vulnerability that allows remote code execution (RCE) was identified with the help of artificial intelligence, and the exploit was developed in roughly two days; building the worm took an additional week. Traditionally, creating malware of this scale would have required several months and a larger team, but the researchers claim that AI handled most of the technical work while humans set objectives and validated the process’s safety. This case illustrates how generative tools can accelerate the discovery and exploitation of vulnerabilities, dramatically reducing the time and resources needed. The story is significant because it demonstrates a new level of threat to mobile security, where AI‑driven automation could enable the rapid creation of more sophisticated, widely spread attacks, forcing the industry to strengthen defenses and reassess the risks of integrating AI into security workflows.
Read the original article on Simon Willison
This summary is an informational synthesis produced by dataqbs.com. All rights to the original content belong to its author and the cited media outlet. We act solely as curators of technology news and claim no authorship.