Researchers say they used AI to build a zero‑click worm that hijacks WeChat accounts and spreads on iOS and Android; Tencent says it patched the vulnerability
| Source: Techmeme | Original article
AI researchers demonstrated a zero‑click worm that can infiltrate WeChat accounts and propagate on iOS and Android devices; Tencent says it has patched the flaw.
Researchers have demonstrated that artificial‑intelligence tools can be used to create a zero‑click worm capable of compromising WeChat accounts and propagating on both iOS and Android devices. The proof‑of‑concept, disclosed by a team of AI specialists, shows that the malware can infiltrate a phone without any user interaction, then leverage the ubiquitous WeChat messaging platform to spread laterally across smartphones. According to the New York Times report, the researchers estimate the technique could have affected “hundreds of millions of devices” if deployed in the wild.
Tencent, the owner of WeChat, confirmed that it has patched the underlying vulnerability after being alerted to the AI‑crafted exploit. The company’s response underscores the growing pressure on large tech firms to address security flaws that are now being discovered through automated, AI‑driven methods rather than traditional manual analysis.
The episode matters because it illustrates a shift in the threat landscape: AI is no longer just a defensive asset but also a potent tool for attackers to automate the discovery and weaponisation of zero‑day bugs. A zero‑click worm that works across the two dominant mobile operating systems raises the stakes for users, developers and regulators, especially given the sheer scale of WeChat’s user base.
Going forward, observers will watch for further disclosures of AI‑generated exploits, the speed at which platform owners can deploy patches, and any indication that malicious actors have adopted similar techniques in the wild. The incident also fuels debate over responsible disclosure practices for AI‑derived vulnerabilities and may prompt tighter coordination between security researchers, AI labs and the companies whose software is targeted.
Sources
Back to AIPULSEN