AI-powered exploit targets WeChat, prompting calls for US-China cyber cooperation

US security firm Calif used AI to identify a critical flaw in Tencent's WeChat app, allowing remote account takeover via an unanswered voice call. The company developed an exploit called WeWorm within a week, and Tencent patched the bug in late August. The incident highlights the speed of AI-driven cyber threats and has renewed calls for bilateral cooperation.
The vulnerability was identified in July by Calif's AI system, and the experimental exploit, named WeWorm, was constructed in just over a week. Tencent deployed a server-side patch in late August, which required no action from users, and stated that there is no indication the flaw was exploited before the fix.
The research highlights how AI drastically shortens the timeline for developing sophisticated cyberweapons. Calif noted that tasks previously demanding months of effort from large engineering teams can now be largely automated, underscoring the escalating pace of digital threats facing major platforms like WeChat.
This incident could reshape trust in widely used communication platforms, as users may become wary of even passive interactions like unanswered calls. It may also intensify diplomatic pressure on Washington and Beijing to formalize cyber norms, given that AI accelerates offensive capabilities faster than defensive responses. For the broader tech industry, this serves as a stark reminder that AI-driven discovery demands equally rapid, coordinated patching mechanisms across borders.