
What happened
Researchers at A Security discovered a major vulnerability in Zoom's annotation feature that allowed attackers to run malicious code on victims' devices during meetings. The flaw was uncovered using fewer than 20 prompts on publicly available AI models, and Zoom issued a patch on Tuesday covering Windows, macOS, Linux, Android, and iOS.
Why it matters
The exploit required no action from victims and left no visual trace of the compromise, making it particularly dangerous. Vulnerability researcher Idan Levcovich noted that "producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons" — but A Security accomplished it in a single day using widely accessible AI tools, suggesting the barrier to executing sophisticated attacks has dropped significantly.
What to watch
Users should ensure they have applied Zoom's patch across all their devices. The incident underscores how AI models available to the general public can now be used to discover and exploit security flaws that previously required state-level resources.
Summaries like this, in your inbox every morning.
The Zoom vulnerability represents a watershed moment in the speed and accessibility of exploit development. Historically, uncovering and weaponizing zero-day flaws required elite teams with substantial budgets, resources that governments closely monitored. A Security's discovery using fewer than 20 AI prompts on off-the-shelf models suggests that barrier has collapsed. The annotation feature flaw is particularly insidious because it required no user action and left no trace—the hallmark of a sophisticated attack—yet it fell to a commercial tool in a single day.
The timing reflects a broader shift in the security landscape: as large language models and AI agents become more capable at reasoning through code and vulnerability patterns, the cost and skill floor for launching serious attacks has plummeted. Zoom's rapid patch across five major platforms (Windows, macOS, Linux, Android, iOS) demonstrates both the severity the company assigned and the urgency of limiting exposure. For organizations relying on Zoom, the incident serves as a concrete warning that vulnerabilities once assumed to require state-level sophistication may now be within reach of smaller teams armed with accessible AI.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Google announced Gemini 4 Argon on September 30, saying DeepMind's own evaluation beat GPT-6 Astra, Claude Fab…

OpenAI dismissed three researchers, according to reports, after highly confidential information was shared wit…

Anthropic PBC reportedly aims to begin marketing its IPO the week of Nov
AI CEOs huddled around US president Donald Trump on Tuesday to sign an AI safety accord

Palo Alto Networks' Idira shipped August features to govern AI agents — MCP access policies limiting which too…

A US government AI chatbot rewrote Minecraft's "End Poem" into a bureaucratic satire, according to BigGo Finan…
