Calif Research称AI加速WeChat蠕虫开发
材料显示AI或在压缩漏洞利用开发周期,安全风险值得跟踪但尚待验证。
Simon Willison引用Calif Research对WeWorm演示的发布说明:该团队称其实现了可通过WeChat通话在iOS和Android传播的零点击蠕虫,受害者无需接听或操作手机;即使接听,也不会听到声音但利用仍会成功。该团队还称,在AI协作下约两天发现漏洞并写出远程代码执行(RCE)利用,随后用一周完成蠕虫;人类主要负责选择攻击目标和安全测试判断。摘录未提供漏洞技术细节、复现材料或独立验证。
⚠ 原始材料信息有限,摘要从简
原文摘录 Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...] The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...] Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week. A worm at this scale used to be the kind of thing that t