
Researchers at A Security discovered a critical vulnerability in Zoom's annotation feature that could let attackers run malicious code on meeting participants' devices, steal data, or activate cameras and microphones—all without the victim noticing.
Remarkably, the flaw was uncovered using fewer than 20 prompts on publicly available AI models, work that would historically have required nation-state effort.
Zoom patched the vulnerability on Tuesday across all major platforms.
What happened
Researchers at A Security discovered a major vulnerability in Zoom's annotation feature that allowed attackers to run malicious code on victims' devices during meetings. The flaw was uncovered using fewer than 20 prompts on publicly available AI models, and Zoom issued a patch on Tuesday covering Windows, macOS, Linux, Android, and iOS.
Why it matters
The exploit required no action from victims and left no visual trace of the compromise, making it particularly dangerous. Vulnerability researcher Idan Levcovich noted that "producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons" — but A Security accomplished it in a single day using widely accessible AI tools, suggesting the barrier to executing sophisticated attacks has dropped significantly.
What to watch
Users should ensure they have applied Zoom's patch across all their devices. The incident underscores how AI models available to the general public can now be used to discover and exploit security flaws that previously required state-level resources.
Zoom faced a critical security crisis this week after researchers at A Security uncovered a major vulnerability in the platform's annotation feature—a capability that lets users draw on their screen while sharing it with meeting participants. By exploiting this feature, an attacker could join or host a meeting and execute malicious code directly on victims' devices, potentially stealing data, activating cameras or microphones, or installing malware. The attack was particularly dangerous because it required no action from the victim and produced no visual warning of compromise.
What made the discovery extraordinary was how it was made. Idan Levcovich, a vulnerability researcher at A Security, noted in the company's blog post that "producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons." Yet A Security achieved a working exploit in a single day using fewer than 20 prompts on publicly available AI models—tools anyone can access. This dramatic shift in the cost and timeline for discovering sophisticated vulnerabilities reflects the growing capability of large language models and AI agents to reason through security patterns and code vulnerabilities.
Zoom addressed the flaw on Tuesday by issuing a patch across Windows, macOS, Linux, Android, and iOS. The breadth and speed of the fix underscored the company's recognition of the threat's severity. For users, the incident serves as a concrete reminder that the technical barrier to discovering and exploiting previously nation-state-level vulnerabilities has eroded, and that keeping software up to date is no longer a convenience but an immediate security imperative.
The Zoom vulnerability represents a watershed moment in the speed and accessibility of exploit development. Historically, uncovering and weaponizing zero-day flaws required elite teams with substantial budgets, resources that governments closely monitored. A Security's discovery using fewer than 20 AI prompts on off-the-shelf models suggests that barrier has collapsed. The annotation feature flaw is particularly insidious because it required no user action and left no trace—the hallmark of a sophisticated attack—yet it fell to a commercial tool in a single day.
The timing reflects a broader shift in the security landscape: as large language models and AI agents become more capable at reasoning through code and vulnerability patterns, the cost and skill floor for launching serious attacks has plummeted. Zoom's rapid patch across five major platforms (Windows, macOS, Linux, Android, iOS) demonstrates both the severity the company assigned and the urgency of limiting exposure. For organizations relying on Zoom, the incident serves as a concrete warning that vulnerabilities once assumed to require state-level sophistication may now be within reach of smaller teams armed with accessible AI.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Security researchers led by Alexander Panfilov discovered a vulnerability in the APIs of all major AI provider…

Apple is developing an iOS feature called Apple Reference Image that embeds provenance metadata into iPhone ph…

Meta CEO Mark Zuckerberg published a 6,500-word essay Monday outlining his vision for artificial intelligence…

ServiceNow has announced AI-powered agents designed to operate within security operations centers (SOCs), auto…

CrowdStrike and Palo Alto Networks jumped more than 5% to new highs on Monday following the Black Hat cyber co…

Rep. Greg Casar (D-Texas) and 18 other House Democrats sent a letter to Speaker Mike Johnson calling for open…

The AI news that matters, in one minute each morning.
Sign up free