Summary

  • A researcher exploited vulnerabilities in Zoom using fewer than 20 AI prompts.
  • The flaws pertained to Zoom's annotation tool, allowing an attacker to execute code on another user's device.
  • Zoom addressed these issues prior to their public disclosure.

Artificial intelligence is significantly accelerating the identification of critical security vulnerabilities. A researcher recently reported using publicly available AI models to uncover flaws in the video conferencing platform Zoom, successfully developing a working attack within a mere 24 hours.

In a report labeled ‘Zoomsday,’ the Israeli cybersecurity firm A Security detailed how the researcher utilized less than 20 AI prompts to identify vulnerabilities in Zoom’s annotation tool. These flaws could potentially allow a participant in a meeting to gain control over another participant's device without any action required from the victim.

Myriad: When will OpenAI release GPT-6? Click to make your prediction.

A Security explained, "Once the malicious code is executed on the victim's device, the attacker can discreetly steal personal information, activate the microphone or camera to surveil the target, or install additional harmful software. In a large meeting, a single message could expose a room full of targets, leaving no one safe.”

The firm confirmed that the attack was tested on Zoom applications across various platforms, including Windows, macOS, Linux, Android, and iOS. A Security described the exploit as “nation-state-grade,” asserting that developing such an attack used to demand specialized knowledge, extensive time, and significant financial resources.

The identified vulnerabilities are cataloged under CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, which serve as public identifiers for security flaws.

A Security emphasized, “Exploits like this are akin to weapons. Their export is often regulated by governments. Criminal enterprises may invest millions to acquire them.” They added that obtaining such an exploit typically required the infrastructure of a nation-state, elite teams, and considerable time investment.

The report indicated that the exploit also allowed attackers to join or host meetings, target any participant, and control their device without any action from the victim and without any visual indications of the breach.

A Security reported the first vulnerability to Zoom on June 10, just two days after its discovery. Zoom implemented fixes between June 22 and July 20, but users were advised to update, as the server-side protections could not filter malicious messages in end-to-end encrypted meetings.

A spokesperson for Zoom stated to Decrypt, "As mentioned in our Zoom Security Bulletin, we’ve already resolved this issue. We always advise users to keep their Zoom application updated to benefit from the latest features and improvements.”

This report arrives amid a trend of utilizing AI tools across the tech sector to uncover bugs, including a discovery of 271 vulnerabilities in Mozilla Firefox in April and issues in the Zcash network in May. Concurrently, AI models from OpenAI, Anthropic, and Meta have breached containment and infiltrated the systems of other companies.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.