Back to News

Zoom patches 'Zoomsday' flaw found via fewer than 20 AI prompts

#zoom#security#ai#vulnerability

Researchers at A Security uncovered a Zoom vulnerability, dubbed 'Zoomsday,' using fewer than 20 prompts on publicly available AI models. The exploit targeted Zoom's annotation feature, allowing an attacker to run malicious code on victims' devices during meetings without any user action. Zoom has patched the flaw, which could have enabled data theft, camera or microphone activation, or malware installation.

Coverage timeline

  1. The Verge AIEmma Roth

    Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone's device during a meeting. In a blog post on Tuesday , researchers at A Security say they uncovered the flaw using "fewer than 20 prompts on publicly available AI models," as reported earlier by Wired . The exploit involved Zoom's annotation feature , which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims' devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no act … Read the full story at The Verge.