CityLab researchers exploited MD5's weakness to answer questions about the system. While not a real problem in practice, it seems clear MD5 was not an ideal choice.
From the article, the researchers generated forbidden and allowed images with a colliding hash to prove WeChat was using MD5. The allowed image was banned in the future as a result.
However, MD5 collision generation has some constraints. It's very hard make an image collide with a particular known hash, but it's feasible (5 hours with a large GPU) to take two images and modify them until their hashes collide. Practically this means exploitation opportunities are rather limited, but a forced collision being possible at all seems non-ideal for an adversarial use case. There's also the risk that future cryptanalysis will further weaken MD5. Seems clear to me WeChat just should have used something like sha256.
With a billion people using phones, "good enough" is probably good enough.
Given the scale and scope of the Chinese security apparatus, anyone capable of using a GPU to hash out collisions is probably already known to the state. And the handful of collisions are probably not important enough to worry about -- a stealthy Winnie The Poo image isn't a big deal.
BLAKE2b would have been the perfect choice given the adversarial nature, as it much secure and faster than MD5. [2]
MD5 is so broken, it's really poor choice for any use case - cryptographic (fundamentally broken) or not (fundamentally slow).
[1] http://ticki.github.io/blog/seahash-explained/
[2] https://leastauthority.com/blog/BLAKE2-harder-better-faster-...
When action is taken on the first image, the collided image could also be censored.
That being said, you could probably create a pair of colliding images, give one to a news outlet or something, then later post the second (presumably banned) one. The app would on short notice need to decide between banning neither or banning both.
Yeah they did this - except the contraband was automatically recognised and both images were banned via hash.