Today we published WeWorm. All it takes is one phone call. You don't have to answer. Within seconds, your WeChat account is compromised and can be used to call your friends and spread the attack further.
Working with AI, our team found the bug and wrote the first RCE exploit in about two days. We reported it to Tencent, and our exploit has now been mitigated for all users.
We hope this work sets an example. The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them.
AI gives us an opportunity to find and fix vulnerabilities faster than ever, and we should work together to make the world safer for everyone.
Read our story and watch the demos: https://calif.io/research/weworm.
The New York Times also spent time following our work and published their story today: https://archive.is/arHsF

