Urgent.News

What's breaking now, across thousands of outlets.

AI

AI builds worm that could hijack accounts on China's biggest app with only one unanswered call

A California security firm used artificial intelligence to build a worm that could hijack WeChat accounts through a single unanswered call, putting more than a billion users at risk before the flaw was fixed.

AI builds worm that could hijack accounts on China's biggest app with only one unanswered call

AI researchers at Calif discovered a critical security flaw in China's popular messaging app, WeChat. The bug, named WeWorm, exploited a memory corruption issue in how the app processes voice calls. Tencent, the company behind WeChat, acknowledged the researchers' findings and swiftly patched the vulnerability. Calif's team completed the exploit in just two days using artificial intelligence, which then took another week to develop the worm.

The worm operates silently, launching an attack while the phone is still ringing and leaving the victim unaware. Once inside an account, the attacker can read messages, place calls, and impersonate the account holder. The worm then propagates to the victim's contacts, potentially infecting millions of devices within hours. Tencent's WeChat app has over 1.432 billion monthly active users, making it China's most-used mobile app.

The AI-assisted discovery dramatically reduced the time and resources required to uncover the exploit compared to a traditional approach. The researchers withheld the technical details of the bug, presenting their full analysis at a conference. While WeWorm doesn't directly compromise the phone, it can spread exponentially through the victim's contacts.

Tencent resolved the issue on August 21 and blocked the exploit on their servers, preventing any user impact.

Written by urgent.news from VnExpress International's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at e.vnexpress.net →

More in AI

More from Saturday 12 September →