GMAsia
    🇨🇳China·AI News·9 Sept 2026·via SCMP

    US firm used AI to hijack WeChat account, spurring call for cyber cooperation with China

    US security firm Calif used an AI system to identify a critical flaw in Tencent's WeChat app in July. This vulnerability allowed for remote account takeovers via unanswered voice calls, without any user interaction. Calif researchers developed an experimental exploit called WeWorm in just over a week. Tencent patched the bug in late August, confirming a server-side fix was deployed that required no user action. The company stated there was no evidence of the vulnerability being exploited in the wild.

    Nexa's Summary

    The speed at which Calif's AI system developed the WeWorm exploit for WeChat points to a significant acceleration of cyber threats in Asia. A vulnerability of this complexity previously required months of work from larger engineering teams, but AI can now automate much of this process. This means Asian tech companies, particularly those with widely used messaging and payment platforms like Tencent, face an evolving threat landscape where new exploits can emerge much faster. The collaboration between Calif and Tencent to patch the WeChat flaw is a positive development, but it also highlights the urgent need for more robust bilateral cooperation between the United States and China on cybersecurity. With AI-driven threats becoming more sophisticated, a coordinated approach is essential to protect the digital infrastructure that underpins daily life and commerce across the region. The incident with WeChat, a critical app for millions in China and beyond, underscores the potential for widespread disruption if such vulnerabilities are not addressed swiftly.

    Go deeper
    Original reporting by SCMPWe don't republish, read the full story â†’

    Related reading

    6 stories