Researchers applied a free artificial intelligence tool to analyze TikTok's code to identify vulnerabilities. The team managed to combine the discovered flaws to demonstrate the possibility of remote access to the mobile phone's camera and photos.
This incident clearly shows how AI models can accelerate the process of finding breaches while expanding criminals' capabilities for attack automation. While American laboratories such as Anthropic and OpenAI restrict advanced security features in their chatbots, Chinese models, such as those from DeepSeek and Z.ai, are available for free download and modification.
The startup DepthFirst took advantage of this openness by modifying the GLM model from Z.ai and using it to search for software bugs. The tool discovered vulnerabilities in an open-source component used by TikTok.
In a video analyzed by The Washington Post, a DepthFirst employee showed that the combination of these vulnerabilities allowed remote access to the smartphone's camera and gallery while the user was viewing the application.
The company reported the issue to TikTok, which confirmed the vulnerability and fixed it. Security experts are monitoring how AI is being used to speed up intrusion operations, but the same tools can help companies find weaknesses before malicious actors exploit them.
John Hultqvist, an analyst at Google Threat Intelligence Group, noted that this technology has the potential to enhance the skills of experienced hackers and lower the barrier to entry for people with less technical knowledge. The company Unit 42 has also recorded the use of AI by intrusive groups to search for vulnerabilities, select potential targets, and attempt exploitation.
According to Unit 42, free models still lag behind the most advanced cybersecurity systems, but they are developing rapidly. Kasim Mitani, CEO of DepthFirst, told The Washington Post that users should not trust any application.
Mitani advised regularly updating applications and limiting the permissions granted to them, especially regarding the camera, geolocation, and photos. This recommendation is particularly relevant given the growing ability of AI tools to find errors and accelerate attacks. At the same time, the same technology is actively used by security teams to localize and fix problems before criminals can use them.
