Skip to main content

Zoomsday hack uncovered using fewer than 20 AI prompts

Security researchers discover a critical Zoom vulnerability allowing attackers to hijack every device on a call using public AI models.

AI-written
Inewgen
12 Aug 2026Source: The Verge2 min read (0 views)
Share
Zoomsday hack uncovered using fewer than 20 AI prompts

Stock photo for illustration only, not from the actual event

Font size
  • Security researchers at A Security uncovered a major vulnerability in Zoom.
  • The exploit was developed using fewer than 20 prompts on public AI models.
  • The attack required zero user action and left no visual cue on victims' screens.
  • Zoom released a security patch on Tuesday to address the flaw across platforms.

Zoom has deployed a security patch to fix a major vulnerability that could let malicious actors hijack any user's device during an active meeting. According to a blog post published on Tuesday by researchers at A Security, the flaw was uncovered using fewer than 20 prompts on publicly available artificial intelligence models, as initially reported by Wired.

The exploit targeted Zoom's annotation feature, which lets participants draw directly on their screens while sharing content with other attendees. By leveraging this vulnerability, an attacker joining or hosting a meeting could execute malicious code on the devices of other participants. This allowed unauthorized data theft, activation of webcams or microphones, and malware installation without requiring any action from the victims and displaying no visual warning of the breach.

20Prompts or fewer used to uncover the flaw

"Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons. A Security did it in a single day, with an AI agent and models anyone can access today."

Idan Levcovich

Idan Levcovich, a vulnerability researcher at A Security, noted in the blog post that engineering such exploits historically required elite teams and months of dedicated effort, highlighting how accessible AI technologies have dramatically accelerated the timeline.

This incident marks a critical turning point in cybersecurity, demonstrating how readily accessible generative AI models can compress vulnerability research timelines from months down to a single day. It underscores an urgent need for software developers to accelerate vulnerability patching cycles as AI-driven threat intelligence becomes democratized for both defenders and potential attackers.

Zoom issued the fix on Tuesday, applying the necessary security updates to protect the application across Windows, macOS, Linux, Android, and iOS devices.

Source: The Verge

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article