AI Safety 🇷🇺 12.08.2026 00:03

Critical Zoom Vulnerability Exploited in One Day Using Ordinary AI Models

Researchers from A Security created a working exploit for a critical Zoom vulnerability, dubbed Zoomsday, in just one day using public AI models. The flaw allowed remote code execution on participants' devices via the annotation feature, and Zoom has since released fixes for all major platforms.
Zoom has fixed a serious vulnerability that allowed hackers to covertly take over devices of video conference participants. Researchers from the company A Security created a working exploit in just one day using publicly available AI models. The vulnerability, named Zoomsday, was related to the annotation feature, which allowed users to draw marks on the shared screen. To launch an attack, an attacker only needed to start a meeting or join someone else's conference, after which they could remotely execute malicious code on the devices of other participants. This gave access to their data, unauthorized activation of cameras and microphones, and allowed installing malware, according to The Verge. Victims did not need to take any action, and there were no visual signs of device compromise on the screen. Idan Levcovich, a vulnerability researcher at A Security, noted in a company blog that creating such exploits was previously considered a state-level task requiring elite teams, months of work, and large budgets. The researchers created the working exploit with the help of an AI agent and only 20 queries to public AI models. After the disclosure, Zoom released fixes for applications on Windows, macOS, Linux, Android, and iOS. The Verge notes that the incident actually confirmed the fears of cybersecurity experts: tools that were previously available only to a narrow circle of professionals can now be used to create sophisticated attacks by any user of public neural networks.
Source: 3DNews — original
Our earlier posts on this topic ↓
Fresh news