Simon Willison’s Weblog
Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...] The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...] Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week. A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely.
Recent articles
Some thoughts on the Navier–Stokes Millennium Prize Problem - 8th September 2026
The Pelican comparison grid for Astra is pretty interesting - 4th September 2026
OpenAI's rogue agents were caught communicating via public wikis - 4th September 2026
This is a quotation collected by Simon Willison, posted on 10th September 2026 .