News

Critical Zoom Vulnerability Discovered Using AI-Assisted Research Now Patched

A team of security researchers has identified and disclosed a significant vulnerability in Zoom that could have allowed malicious actors to take complete control of a victim's device simply by joining the same video call.

The flaw, dubbed "Zoomsday" by researchers at A Security, resided in Zoom's annotation feature—the tool that allows meeting participants to draw or write on a shared screen. By exploiting this feature, an attacker could execute arbitrary code on other participants' devices without requiring any interaction from the victims beyond joining the call.

Once compromised, an attacker could have potentially accessed sensitive data, activated cameras or microphones, and installed malware on the affected device.

Notably, the researchers identified the vulnerability using fewer than 20 prompts with publicly available AI models, highlighting how artificial intelligence tools are increasingly being used to assist in security research—and, conversely, how they could be leveraged to discover similar flaws at scale.

Zoom has since released a patch addressing the vulnerability. Users are encouraged to ensure their Zoom clients are updated to the latest version to protect against this and other potential security issues.

The discovery underscores the ongoing challenges in securing collaboration software, which has become essential infrastructure for both personal and professional communication. As video conferencing platforms continue to add features to improve user experience, each new capability can potentially introduce attack surfaces that require careful security review.

Sources