Research

Researchers Use AI to Find Critical Zoom Vulnerability

Security researchers have leveraged public artificial intelligence models to discover a severe, zero-click vulnerability in Zoom that could allow attackers to hijack meeting participants' devices.

The Verge AI21 hrs agoResearch
Image: The Verge AI

Security firm A Security recently demonstrated how easily advanced vulnerabilities can be uncovered by using public artificial intelligence models to find a major security flaw in Zoom. The researchers revealed they successfully mapped out and exploited the critical vulnerability using fewer than 20 prompts on widely available AI systems. Zoom has since released a patch to address the issue, which affected its applications across Windows, macOS, Linux, Android, and iOS platforms.

The security flaw resided in Zoom's screen-sharing annotation feature, which lets participants draw on a shared screen during a live call. By exploiting this component, an attacker could join or host a meeting and execute malicious code on the devices of other attendees. This zero-click exploit required no interaction from the victims and left no visual indication that a compromise had occurred, allowing attackers to silently steal data, activate microphones or cameras, and install malware.

According to A Security researcher Idan Levcovich, developing this kind of functional exploit historically required "nation-state work" involving elite teams, months of effort, and massive government-regulated budgets. However, the firm managed to replicate these results in just a single day by utilizing an AI agent and standard commercial models. The rapid discovery highlights how AI is lowering the barrier to entry for finding complex software vulnerabilities.

For cybersecurity practitioners and software developers, this development signals a dramatic shift in the threat landscape. The ability of relatively simple AI prompts to automate the discovery of deep system flaws means that both defensive and offensive security operations are accelerating. Software vendors must now anticipate that malicious actors will use similar AI-driven methodologies to scan for zero-day vulnerabilities, making rapid patch deployment and AI-assisted code auditing essential practices for modern software security.

This is our own summary of reporting by The Verge AI

More in Research