Calif Research released a demo of WeWorm, a zero-click worm that leverages WeChat calls across iOS and Android. The exploit does not require user interaction, even if the victim answers the call. The target device executes code remotely without any direct user action.
Working with AI, the team identified the bug and created the first remote code execution (RCE) exploit in approximately two days. Building the worm took an additional week. This process was previously a task requiring a larger team and several months.
The research team provided judgment regarding target selection and safe testing procedures. AI handled much of the technical work involved in developing the worm.
This demonstration illustrates the potential of AI to accelerate security research and development, particularly in areas like vulnerability discovery and exploit creation. Source: https://simonwillison.net/2026/Sep/10/calif-research/