Zoom fixes security flaw found with fewer than 20 AI prompts
Zoom has patched a serious security vulnerability that researchers at A Security uncovered using publicly available AI models. The flaw could have let an attacker seize control of a victim's device during a meeting without any action on their part.

Zoom has released a fix for a serious security vulnerability that could have allowed an attacker to take over another user's device during a video call. The flaw was detailed in a blog post published Tuesday by researchers at security firm A Security, who said they discovered it using fewer than 20 prompts on publicly available AI models. The finding was first reported by Wired.
The vulnerability was tied to Zoom's annotation feature, which lets users draw on their screen while sharing it with other meeting participants. By exploiting this flaw, an attacker could join or host a meeting and then run malicious code on victims' devices. That could open the door to stealing data, activating a camera or microphone without permission, or installing additional malware.
Particularly concerning is that the attack required no action from the victim and left no visible sign that a device had been compromised.
Previously nation-state-level work
A Security researcher Idan Levcovich wrote in the blog post that building a working exploit like this had traditionally been the domain of nation-state actors, requiring elite teams, months of effort, and budgets governments treat as weapons-grade spending. His company managed to do it in a single day using an AI agent and models that are accessible to anyone today.
Zoom issued a fix for the vulnerability on Tuesday. The flaw had affected the Zoom app across Windows, macOS, Linux, Android, and iOS.

