WeChat fixes flaws after US firm shows AI cyberattack worm could hijack accounts
BEIJING, Sept 9 — The operator of Chinese mega-app WeChat said Wednesday it had fixed software weaknesses flagged...
Beijing, September 9 — Chinese messaging and digital payment giant WeChat announced on Wednesday that it had patched software vulnerabilities highlighted by a US cybersecurity firm. The firm, named Calif, described itself as a group of "hackers" whose mission is to "make the internet safer for everybody" by identifying flaws in various apps and programs.
Calif claimed it utilized artificial intelligence to create a cyberattack "worm" capable of spreading from phone to phone merely by making calls to WeChat contacts. Unlike traditional attacks, the victim does not need to answer the call or engage with their device at all. Exploitation reportedly takes only seconds, granting full control of the WeChat account, which in turn allows for reading, sending messages, making calls, and acting on behalf of the victim.
When combined with other mobile phone bugs, Calif's "WeWorm" could even assume full control of a device.
Tencent, the Chinese tech behemoth behind WeChat, informed AFP of a "potential security issue" flagged by Calif. "We investigated the report and have implemented a fix. The fix was deployed on our servers and is now live for all users — no app update or any other action is required," said Tencent. "We have no evidence that the issue was exploited or that any user was affected," the statement added, expressing gratitude to the researchers for bringing the matter to their attention.
The report on WeChat's security flaw has drawn attention to the growing risk posed by advanced AI systems in uncovering previously unknown cybersecurity vulnerabilities. Calif stated it had used AI to detect the security vulnerability in WeChat within two days and to construct the worm within another week - a process that typically took a larger team months.
"We are publishing our findings to raise public awareness," stated Calif's blog post. "AI is putting these capabilities in the hands of less-skilled actors, leaving ordinary users at unprecedented risk."
As AI capabilities advance, discussions surrounding online safety and security are expected to feature prominently in upcoming high-level meetings, including a planned White House summit between US President Donald Trump and Chinese President Xi Jinping. Calif's chief, Thai Duong, emphasized on social media that "the US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them."
Written by urgent.news from Malay Mail's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.