AI Cyberattack on WeChat Exposes Vulnerabilities, Prompts US-China Talks
AI-generated context summary requested by a Free News Reader user. Sourced via Gemini from publicly available information — no paywalled content was accessed.
You hit a paywall. Here’s the context on this topic based on publicly available information. We did not access any paywalled content. View original article.
AI Cyberattack on WeChat Exposes Vulnerabilities, Prompts US-China Talks
- A cybersecurity firm recently demonstrated an AI-powered computer worm, dubbed "WeWorm," capable of exploiting a vulnerability in WeChat, a messaging app with over 1.4 billion users.
- The "WeWorm" exploit, developed by Palo Alto-based security company Calif, could hijack WeChat accounts through unanswered voice calls and was patched by Tencent in late August after Calif's notification.
Full Summary — powered by AI
A recent demonstration of an AI-powered cyberweapon, named “WeWorm,” has highlighted significant vulnerabilities in China’s digital infrastructure, particularly within the widely used WeChat messaging application. Developed by the US cybersecurity firm Calif, the “WeWorm” is a computer worm that could have exploited a critical flaw in WeChat, potentially compromising over a billion accounts.
The “WeWorm” demonstrated the ability to self-replicate and spread through WeChat users’ friend lists by simply initiating a voice call, without requiring the victim to answer or interact with their device. This “zero-click” vulnerability, identified as a memory corruption issue in WeChat’s VoIP stack, allowed for full control of a WeChat account within seconds, enabling an attacker to read messages, send new ones, and make calls on the victim’s behalf. Calif researchers, who developed the exploit in just over a week with AI assistance, notified Tencent, WeChat’s parent company, in July, and the vulnerability was patched in late August. Tencent has stated there is no evidence the vulnerability was ever exploited in the wild.
This incident has amplified calls for urgent AI safety talks between Beijing and Washington. Both the United States and China are preparing for bilateral discussions in mid-September to address the growing risks posed by artificial intelligence, particularly AI-driven cyber threats. These talks, reportedly led by US Treasury Secretary Scott Bessent on the American side, are expected to precede a high-level summit between President Donald Trump and Chinese President Xi Jinping on September 24. The US aims to propose joint cooperation to monitor AI-driven cyber threats and has suggested that AI laboratories in both nations share safety data and “police themselves” to prevent AI-linked cyber incidents.