Zoom has released a critical patch for a security vulnerability that allowed attackers to take control of participants' devices during a meeting. The flaw, dubbed "Zoomsday," was identified by researchers at A Security who utilized "fewer than 20 prompts on publicly available AI models" to uncover the exploit.

The Mechanics of the Exploit

The vulnerability resided within Zoom’s annotation feature, a tool that allows users to draw on their screen while sharing it. According to the researchers, an attacker could join or host a meeting and run malicious code on victims’ devices. This access granted the ability to steal sensitive data, activate cameras or microphones, and install malware.

Crucially, the attack required no interaction from the victims and showed "no visual cue indicating the compromise," making it a seamless "zero-click" threat.

AI: The New Frontier for Vulnerability Research

The speed and ease with which the flaw was found highlight a significant shift in cybersecurity. Idan Levcovich, a researcher at A Security, noted that producing a working exploit of this caliber previously required "nation-state work: elite teams, months of effort, budgets that governments regulate as weapons." Instead, the team accomplished it in a single day using an AI agent and models accessible to the public.

Zoom issued a fix for the vulnerability on Tuesday. The patch applies to the application across all major platforms, including Windows, macOS, Linux, Android, and iOS.