This one's worth opening because it puts a concrete number on AI-assisted vulnerability research: two days to find the bug, one more week to build a cross-platform worm. Calif's demo shows an attacker calling a WeChat friend, hijacking their account while the phone is still ringing, then using that account to call the next victim. No answer required. They demoed the chain on a Pixel 10a and an iPhone 17e.
I'd discount the hype a bit. Technical details are withheld for a future conference talk — all we know is it's a memory corruption bug in WeChat's VoIP stack. Tencent got the report in late July and had server-side mitigations rolled out to all users by late August, no client update needed. That's a fast turnaround.
The useful bit isn't "WeChat is unsafe." It's that VoIP stacks, video codecs, and other non-traditional attack surfaces in super-apps are about to get a lot more scrutiny. Calif says they're running the same research across other messaging apps. The wild part is the speed: two days from discovery to working RCE exploit, with AI doing most of the heavy lifting. If that cadence holds, the window between bug discovery and patch is shrinking — but so is the barrier for less skilled attackers.