Zoom has patched a major security vulnerability that could have allowed an attacker to hijack a user’s device during a meeting. Researchers detailed the flaw in a blog post published on Tuesday, stating they uncovered it using fewer than 20 prompts on publicly available AI models.
The exploit centred on Zoom’s annotation feature, which lets participants draw on their screen while sharing it with others in a meeting. By abusing this function, an attacker could join or host a meeting and then run malicious code on victims’ devices.
How the attack worked
Once the flaw was triggered, an attacker could steal data, switch on the camera or microphone, or install malware on a target’s machine. The attack required no action from the victim and showed no visual cue indicating that a device had been compromised. That combination made the vulnerability particularly dangerous, as those affected would have no obvious sign that anything was wrong during an ordinary meeting.
The technique, dubbed ‘Zoomsday’, worked across the Zoom application on Windows, macOS, Linux, Android, and iOS, giving it broad reach across desktop and mobile platforms alike.
AI lowers the barrier to exploits
Idan Levcovich, a vulnerability researcher, said that producing a working exploit of this kind had traditionally been nation-state work, involving elite teams, months of effort, and budgets that governments regulate as weapons. In this case, the research team said it achieved the result in a single day using an AI agent and models that anyone can access today.
The finding highlights how AI models are reshaping the economics of security research, compressing work that once demanded significant time and specialist resources into a far shorter timeframe. It also underscores the speed at which such tools can identify weaknesses in widely used communication software relied upon by businesses and individuals around the world.
Zoom issued a fix for the vulnerability on Tuesday, addressing the flaw across every affected operating system.
Source
Image: theverge.com