Researchers at Calif, a Palo Alto-based security company, recently developed a computer worm called WeWorm using advanced artificial intelligence models. The tool exploited a vulnerability in WeChat that allowed it to spread automatically from one account to contacts saved in the address book.

The worm operated without requiring any user action such as clicking a link or answering a call, though it activated if a targeted user picked up or allowed the call to ring. It worked across both Apple's iOS and Google's Android platforms, marking the first known worm with that cross-device capability.

Experts noted the attack could have compromised hundreds of millions of devices within hours due to its exponential propagation method. WeChat, owned by Tencent, serves as a dominant messaging and social platform in China with a vast user base.

Tencent confirmed the vulnerability after being contacted by the researchers and stated that it had been fixed. The company reported no evidence of any user accounts being compromised and indicated that no customer app updates were necessary.

The demonstration highlights the accelerating capabilities of AI in cybersecurity threats. The Calif team assembled the worm in just over a week, underscoring how quickly such tools can be created compared to traditional malware development.

This case adds to growing concerns about AI outpacing regulatory and defensive measures. The worm's design leveraged WeChat's trust mechanisms for contacts, enabling seamless lateral movement once initial access occurred.

No real-world deployment occurred, as the research focused on identifying and disclosing the flaw. The findings were detailed in a summary reviewed by major outlets on Tuesday.