‘Zoomsday’ hack uncovered using fewer than 20 AI prompts

← Back to the feed

‘Zoomsday’ hack uncovered using fewer than 20 AI prompts

The Verge · 3 hours ago

Zoom has patched a serious security vulnerability, dubbed "Zoomsday" by researchers, that could have allowed an attacker to hijack the device of anyone in a meeting without them noticing. Security firm A Security says it discovered the flaw using fewer than 20 prompts on publicly available AI models, highlighting how AI tools are lowering the bar for finding exploits that would previously have required nation-state-level resources.

The vulnerability exploited Zoom's screen-annotation feature, letting an attacker who joined or hosted a meeting run malicious code on other participants' devices. This could have enabled data theft, covert activation of cameras or microphones, or malware installation, with no action required from the victim and no visible sign of compromise. A Security researcher Idan Levcovich said such an exploit would normally take elite teams months to build, but his firm did it in a single day using an AI agent. Zoom released a fix on Tuesday, covering Windows, macOS, Linux, Android and iOS.

  • Zoom patched a flaw letting attackers hijack call participants' devices.
  • Researchers found it using under 20 AI prompts in a day.
  • Exploit needed no victim action and left no visible trace.

AI Cybersecurity Research Science Technology

Read the full article at the source →