Security researchers say they used publicly available AI models to find a critical Zoom vulnerability in less than a day, with fewer than 20 prompts, and then built a working exploit.
The flaws sat in the protocol behind Zoom’s annotation feature, which lets participants draw on a shared screen. A Security, the digital defense firm that found the bugs, said an attacker on any call using screen sharing could run malicious code on victims’ devices, steal data, turn on cameras or microphones, or install malware. The attack required no action from the victim and showed no visual cue.
Zoom issued an advisory and began rolling out server and client fixes on August 11. The flaw affected Windows, macOS, Linux, iOS, and Android.
“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” said Idan Levcovich, a vulnerability researcher at A Security. “We did it in a single day, with an AI agent and models anyone can access today.”
The finding is the latest example of AI lowering the barrier to vulnerability discovery. A Security cofounder Omer Gull said the same work used to take a team of five people about six months. The researchers discovered the bug in early June and warned that joining a call is itself a gesture of trust attackers could abuse.