Zoom flaw let attackers hijack devices with zero clicks — patched after AI found it in a day
Curated by the Inblix editorial team
A vulnerability that would have once taken a nation-state team months to exploit was cracked in a single day using fewer than 20 prompts on publicly available AI models. That’s the stark reality laid out by researchers at A Security, who uncovered a critical remote code execution flaw in Zoom’s annotation feature — a bug that let an attacker hijack any participant’s device without them clicking anything, seeing anything, or even suspecting a thing.
The exploit, which researchers dubbed ‘Zoomsday,’ turned Zoom’s screen-sharing annotation tool into an attack vector. A malicious meeting host or participant could run arbitrary code on victims’ machines across Windows, macOS, Linux, Android, and iOS. Once in, they could steal data, activate cameras and microphones, or drop malware. There was no visual cue. No warning. Just full compromise.
“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” Idan Levcovich, a vulnerability researcher at A Security, wrote in the disclosure. “A [Security] did it in a single day, with an AI agent and models anyone can access today.” That line should rattle people. The same AI acceleration that’s letting developers ship features faster is also compressing the timeline from vulnerability discovery to weaponization. What used to require specialized expertise and significant funding now looks more like a weekend project for someone who knows how to prompt an LLM effectively.
Zoom issued a fix on Tuesday, and users should update immediately — this isn’t the kind of patch you sit on. The broader story here isn’t really about Zoom at all. It’s about how AI is fundamentally reshaping the economics of offensive security research. When the barrier to finding critical zero-days drops to 20 prompts and a day’s work, every software vendor’s patching cadence suddenly looks glacial. The researchers didn’t just find a bug; they demonstrated that the old assumptions about what’s hard in security no longer hold.
💡 Key Takeaways
- AI reduced the exploit development timeline from months of elite effort to a single day and fewer than 20 prompts, signaling a fundamental shift in offensive security capabilities.
- The 'Zoomsday' vulnerability in Zoom's annotation feature required zero user interaction and left no visual trace, making it a worst-case scenario for meeting participants.
- The exploit affected every major platform — Windows, macOS, Linux, Android, and iOS — meaning no Zoom user was safe without the patch.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.