Zoomsday hack uncovered using fewer than 20 AI prompts
Security researchers discover a critical Zoom vulnerability allowing attackers to hijack every device on a call using public AI models.

Stock photo for illustration only, not from the actual event
- Security researchers at A Security uncovered a major vulnerability in Zoom.
- The exploit was developed using fewer than 20 prompts on public AI models.
- The attack required zero user action and left no visual cue on victims' screens.
- Zoom released a security patch on Tuesday to address the flaw across platforms.
Zoom has deployed a security patch to fix a major vulnerability that could let malicious actors hijack any user's device during an active meeting. According to a blog post published on Tuesday by researchers at A Security, the flaw was uncovered using fewer than 20 prompts on publicly available artificial intelligence models, as initially reported by Wired.
The exploit targeted Zoom's annotation feature, which lets participants draw directly on their screens while sharing content with other attendees. By leveraging this vulnerability, an attacker joining or hosting a meeting could execute malicious code on the devices of other participants. This allowed unauthorized data theft, activation of webcams or microphones, and malware installation without requiring any action from the victims and displaying no visual warning of the breach.
"Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons. A Security did it in a single day, with an AI agent and models anyone can access today."
Idan Levcovich
Idan Levcovich, a vulnerability researcher at A Security, noted in the blog post that engineering such exploits historically required elite teams and months of dedicated effort, highlighting how accessible AI technologies have dramatically accelerated the timeline.
This incident marks a critical turning point in cybersecurity, demonstrating how readily accessible generative AI models can compress vulnerability research timelines from months down to a single day. It underscores an urgent need for software developers to accelerate vulnerability patching cycles as AI-driven threat intelligence becomes democratized for both defenders and potential attackers.
Zoom issued the fix on Tuesday, applying the necessary security updates to protect the application across Windows, macOS, Linux, Android, and iOS devices.
Source: The Verge
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment