Chinese AI Model Can Invade Private Phones, Triggering Security Concerns.

An American startup in San Francisco has successfully hacked into the smartphone camera of a TikTok user with the help of a free artificial intelligence (AI) model provided by a Chinese company. This incident has raised concerns about the lack of restrictions on Chinese AI models.

According to The Washington Post, the cybersecurity startup DepthFirst sought artificial intelligence software to help identify computer vulnerabilities. Instead of choosing top American artificial intelligence companies like Anthropic and OpenAI, DepthFirst opted for an AI model from a Chinese company.

While American artificial intelligence companies restrict their AI models to provide cybersecurity assistance only to specific users who undergo rigorous scrutiny, Chinese companies such as DeepSeek and Z.ai allow anyone to freely download and modify their AI models.

Earlier this year, DepthFirst extensively modified the free GLM AI model from Z.ai and combined it with other tools to create a model capable of delving deep into software to find vulnerabilities that could be exploited by malicious hackers.

The report from The Washington Post mentioned that a video showcasing the software’s capabilities revealed that a DepthFirst employee exploited a series of vulnerabilities in TikTok to remotely access the camera and photo library of a smartphone browsing TikTok.

DepthFirst’s AI vulnerability-finding model identified a vulnerability in an open-source software used by TikTok, allowing attackers to remotely access TikTok users’ phones. The TikTok security team confirmed and patched the vulnerability disclosed by DepthFirst.

Qasim Mithani, CEO of DepthFirst, stated that their AI vulnerability-finding model has discovered dozens of serious vulnerabilities in software used by millions of users. The power of artificial intelligence has convinced him that as AI becomes an increasingly potent tool for cyber attackers, the world is facing a severe challenge.

In April of this year, Anthropic warned that their latest version of the Claude AI model performs well in both network defense and cyber attacks, prompting governments in the US and other countries to assess the potential risks posed by AI.

Anthropic and OpenAI restrict the hacking capabilities of their AI models and only allow vetted companies to use their full functionalities for defensive purposes.

Several months later, Chinese AI models also demonstrated robust network defense and attack capabilities. However, these AI models have few limitations, allowing almost anyone worldwide to access advanced hacking techniques for defense or attack.

“This situation keeps me up at night,” Mithani said.