Security researchers have disclosed a critical vulnerability in Zoom that allowed malicious actors to compromise participants' devices during calls, a flaw Zoom has since patched.
Zoom recently deployed a patch for this significant security flaw, which had the potential for an attacker to seize control of any device within a meeting. In a Tuesday blog post, researchers from A Security detailed their discovery of the vulnerability, remarkably achieved using “fewer than 20 prompts on publicly available AI models,” as initially reported by Wired.
The mechanism behind this exploit leveraged Zoom’s annotation feature, typically used by participants to draw on their shared screens. Exploiting this, an attacker could either join or host a meeting to execute malicious code on victims' devices. This allowed for various nefarious actions, including data theft, remote activation of cameras or microphones, or the installation of malware. Crucially, the attack required no user interaction and presented “no visual cue indicating the compromise,” according to A Security.
Idan Levcovich, a vulnerability researcher at A Security, highlighted the groundbreaking nature of their work in the blog post, stating, “Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons.” He added, “A [Security] did it in a single day, with an AI agent and models anyone can access today.” Zoom promptly released a fix for this vulnerability on Tuesday, affecting its application across Windows, macOS, Linux, Android, and iOS platforms.
The Editorial Staff at AIChief is a team of professional content writers with extensive experience in AI and marketing. Founded in 2025, AIChief has quickly grown into the largest free AI resource hub in the industry.