VECTOR WIREAI INTELLIGENCE
UTC
Refresh Models Deals Regulatory Sources

AI-Built Zero-Click Worm Hacked WeChat Across iOS and Android

Researchers used AI to create a zero-click worm that hacked WeChat accounts across iOS and Android; Tencent says it patched the vulnerability.

Researchers used AI models to build a zero-click worm capable of hacking WeChat accounts and spreading autonomously across iOS and Android devices, according to reporting by the New York Times1,2.

The worm required no user interaction to propagate, a characteristic that distinguishes zero-click exploits as particularly dangerous. Experts cited in the reporting said the attack could have compromised hundreds of millions of devices within hours.

Tencent, which operates WeChat, said it has fixed the vulnerability.

ANALYSIS The episode marks a concrete demonstration of AI systems being used to discover and weaponize software vulnerabilities at scale, moving the threat from theoretical to operational. The zero-click nature of the worm, combined with its cross-platform reach on both iOS and Android, compounds the severity: WeChat's user base spans well beyond China, and a self-propagating exploit of this kind tests the limits of conventional patch-and-respond security models.

Tencent's confirmation that the flaw has been remediated does not address the broader question of how quickly AI-generated exploits can outpace defensive patching cycles, particularly for messaging platforms with massive install bases.