AI-Developed Worm Exploits WeChat Vulnerability, Threatens Over a Billion Accounts

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Cybersecurity firm Calif used AI to develop WeWorm, a zero-click computer worm exploiting a WeChat vulnerability on Android and iOS. The worm could hijack accounts without user interaction and self-propagate via calls, threatening the privacy and security of over a billion users before Tencent patched the flaw.[AI generated]

Why's our monitor labelling this an incident or hazard?

An AI system was used in the development of the worm, which directly led to unauthorized account breaches and propagation of the worm, constituting harm to users' property (accounts) and potentially their privacy and security. The worm's use and spread represent realized harm caused by the AI-assisted exploit. Therefore, this qualifies as an AI Incident.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital security

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

Business function:
ICT management and information security

AI system task:
Content generation


Articles about this incident or hazard