Summary of the Key Points
This news report highlights a overlooked risk: the "accessibility features" originally designed for visually impaired individuals and the elderly on mobile phones have been misused by scammers and malicious software as tools for fraud. The widespread adoption of AI has significantly lowered the threshold for such abuse, with activities ranging from remote-controlled scams to automated video viewing and red envelope (red packet) theft all relying on these permissions. Regulatory authorities and the judiciary are taking action to address this issue by implementing measures such as "dual authorization" policies, reminding ordinary users not to easily relinquish control of their phones for the sake of minor conveniences.
1. Accessibility Features: From Benevolent Intentions to Fraud Tools
Accessibility features were initially created with a humanitarian purpose—helping visually impaired people understand screen content and enabling elderly individuals with mobility issues to use their phones more easily. However, these features grant unprecedented levels of access; they can read all text on the screen (including passwords and chat records) and simulate user interactions, effectively giving the attacker complete control over the phone, like a "super remote control."
The case of Ms. Zhou from Jiangsu is a prime example: scammers convinced her to download a suspicious app, which obtained her accessibility permissions. As a result, her phone went offline, and she nearly lost a 970,000 yuan deposit. She was only able to prevent the loss by removing her SIM card and disconnecting from the network physically. As of April this year, there have been over 1,100 such remote-controlled scams in Beijing, all utilizing these accessibility features.
2. The Rise of AI: Making Malicious Activities More Accessible to Everyone
In the past, it was difficult to use accessibility features for malicious purposes; one needed to understand coding or modify software, which was beyond the capabilities of most people. However, AI has changed this dramatically. With AI tools, automated scripts can be generated in just minutes, and popular "lazy user" apps (such as those that automatically claim red envelopes or watch videos) rely on these permissions to function. Users often grant them without raising any suspicion.
For instance, the "AutoCMD+" app developed by a company in Chengdu could automatically view content on Douyin (TikTok) and claim red envelopes from WeChat. Despite having nearly 38,000 downloads, the app was fined 30,000 yuan for violating China's Anti-Unfair Competition Law due to lack of authorization from both WeChat and Douyin. AI has made it possible for ordinary users to carry out malicious activities.
3. Regulatory Action: Implementing "Dual Authorization" to Curb Abuse
Regulators and the judiciary are now taking steps to restrict the misuse of these permissions, with a focus on the "dual authorization" principle. Third-party apps that wish to use accessibility features to interact with other apps (such as WeChat) must obtain both user consent and official permission from the app owner.
- The Guangzhou Internet Court has ruled in similar cases, ordering malicious apps to stop downloading and stating that user authorization alone is not sufficient;
- A court in California, USA, also ruled in a case involving Amazon and Perplexity: even with user consent, the platform's permission was required.
This approach is like having two layers of security—first, the user must give their consent; second, the app owner (such as WeChat or Douyin) must also approve. This combination helps to prevent unauthorized access to other apps.
4. What Can Ordinary Users Do to Protect Themselves?
It's important to be cautious and not grant accessibility permissions to unfamiliar apps for the sake of minor conveniences. Behind these "lazy user" apps may lie risks such as privacy breaches and account theft.
Next time you encounter an app that requests accessibility permissions, ask yourself: "Is this feature really that necessary?" For example, does it really need access to all your chat records just to claim red envelopes automatically? Your money and personal information on your phone are far more valuable than temporary convenience.
In Summary: Accessibility features are a double-edged sword. The rise of AI has made them more dangerous, but regulatory efforts are in place to address this issue. It's up to you to be mindful and secure your own permissions.