DATANEWS

‘Zoomsday’ Flaw Let Attackers Silently Take Over Devices—and AI Helped Build the Exploit in Under 20 Prompts

WIRED · 2026-08-11

Researchers at A Security disclosed flaws in Zoom’s screen-sharing annotation protocol that could enable silent device takeover, saying publicly available AI models helped uncover and weaponize the vulnerabilities with fewer than 20 prompts.

Why it matters: AI-assisted discovery and weaponization of a silent cross-platform collaboration-tool vulnerability demonstrates how quickly generative AI may compress the vulnerability-research cycle and increase enterprise patching pressure.

Cybersecurity researchers have disclosed a serious Zoom vulnerability that illustrates how rapidly artificial intelligence is changing software-security research. Researchers at A Security found flaws in the protocol Zoom uses for real-time annotation during screen sharing that could allow someone participating in a meeting to silently compromise another participant’s device.\n\nThe attack required no action from the victim and provided no obvious visual indication that a compromise was occurring. A successful attacker could potentially execute code, steal information, install malware or gain access to a device’s camera and microphone. Researchers said the affected functionality existed across Zoom-supported Windows, macOS, Linux, Android and iOS environments. Zoom rolled out fixes on both its servers and client applications.\n\nWhat makes the disclosure particularly important is the role AI played in the research. A Security says publicly available AI models helped uncover the vulnerabilities and produce a working attack with fewer than 20 prompts. That changes the economics of vulnerability discovery: sophisticated exploit-development techniques that once demanded substantial specialist time may increasingly become accessible to much smaller teams.\n\nFor enterprises, the lesson extends beyond Zoom. As AI systems become better at reasoning about code, protocols and attack paths, vulnerability discovery is likely to accelerate for defenders and attackers simultaneously. Organizations may have considerably less time between the existence of an exploitable weakness and the point at which capable adversaries can weaponize it.

Source and attribution →