News 4 u.

THE DAILY EDITION / America/Los_Angeles
Back to the edition

Technology

Tencent fixes WeChat flaw after researchers demonstrate AI-assisted zero-click worm

nytimes.com

Security company Calif says researchers used AI models and human expertise to build a worm capable of taking over WeChat accounts and spreading between iOS and Android users without clicks. Tencent confirmed the vulnerability and said it had fixed it, with no customer updates required and no reason to believe users were affected. The demonstration highlights how AI may accelerate sophisticated exploit development, although projected mass compromise was hypothetical and the researchers said the process required substantial human supervision.

Editorial summary · Publisher article

What matters

  • Compromised accounts could expose messages and enable calls and further account takeovers through trusted contacts.
  • Full control of a phone would require additional vulnerabilities, according to Calif.
  • Calif did not identify the specific AI models used.
  • An external reviewer described potentially exponential spread; the report establishes no mass outbreak.

Context & caveats

  • Claims about cross-platform propagation and development speed are attributed to Calif.
  • Account compromise should not be confused with demonstrated full-device compromise.
Why this made the edition

Detailed research reporting includes vendor confirmation, external assessment and important limits on AI autonomy and actual impact.

Source material
News 4 u.25 stories / 2026-09-08