The flaw allowed for remote account takeovers without user interaction, prompting Tencent to patch the problem after Calif cybersecurity team flagged it
US cybersecurity researchers have demonstrated how artificial intelligence could help hijack WeChat accounts via unanswered voice calls, intensifying concerns about AI-driven cyber threats and prompting renewed calls for bilateral cooperation between the United States and China.
US security firm Calif said on Tuesday that its AI system identified a critical flaw in Tencent Holdings’ widely used messaging and payments app in July. In just a little over a week, researchers developed WeWorm – an experimental exploit that could allow an attacker to take full control of a target’s WeChat account via a simple voice call, without the victim ever picking up the phone.
Tencent patched the bug in late August, according to Calif, which alerted the Chinese tech giant.
A Tencent spokesperson confirmed on Wednesday that a server-side fix was deployed, requiring no user action, and noted there was no evidence that the vulnerability was ever exploited in the wild. Tencent added that it was “grateful to the researchers for bringing this to our attention and working with us”.
The experiment underscores the speed at which AI is accelerating cyber threats. A worm of this complexity previously required months of work from larger engineering teams, but Calif researchers noted that “AI can already do most of the work here”.
The findings left some analysts alarmed.