A security researcher found and exploited Zoom flaws using fewer than 20 AI prompts.
The bugs affected Zoom’s annotation tool and could let an attacker run code on another participant’s device.
Zoom fixed the vulnerabilities before they were publicly disclosed.
AI is making it faster and easier to find serious security flaws. Now, a researcher says he used publicly available models to find vulnerabilities in the video chat platform Zoom and build a working attack in less than 24 hours.
Calling it ‘Zoomsday’ in a report published Tuesday, Israeli cybersecurity firm A Security said a researcher used fewer than 20 AI prompts to uncover flaws in Zoom’s annotation tool that could let someone in a meeting take control of another participant’s device without any action from the victim.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.
“Once the nefarious code is running on the victim’s device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software,” A Security wrote. “In a large call, that’s a room full of targets from a single message, with no safe seat in it.”
According to A Security, the attack was tested on Zoom’s apps for Windows, macOS, Linux, Android, and iOS. The firm called it “nation-state-grade,” arguing that building such an exploit once required specialists, months of work, and a large budget.
The flaws are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. CVEs are public identifiers for security vulnerabilities.
“Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them,” they wrote. “Acquiring one has always required nation-state infrastructure, elite teams, and months of work.”
A Security said the exploit also enables attackers to either join or host a meeting, target any participant, and take over their machine with “no required action from the victim and no visual cue indicating the compromise.”
“It worked in both directions: a compromised presenter could reach every participant, and any participant could reach the presenter,” they wrote.
A Security said it reported the first flaw to Zoom on June 10, two days after discovering it. Zoom released fixes between June 22 and July 20, but users still needed to update because its server-side safeguard could not filter malicious messages in end-to-end encrypted meetings.
“As shared on our Zoom Security Bulletin page, we’ve already resolved this issue,” a Zoom spokesperson told Decrypt. “We always recommend users keep up to date with the latest version of Zoom so that they’re taking advantage of our latest features and updates.”
The report comes as AI tools are being used across the tech industry to uncover bugs, including 271 vulnerabilities in Mozilla Firefox in April and flaws in the Zcash network in May. At the same time, AI models from OpenAI, Anthropic, and Meta have escaped containment and hacked other companies’ systems.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.