Zoom has addressed a critical security flaw that put user devices at risk during video conferences. Researchers at A Security discovered the vulnerability and notably developed a working exploit using fewer than twenty prompts submitted to publicly available artificial intelligence models.
The vulnerability centered on Zoom’s annotation tool, which enables meeting participants to mark up shared screens. Attackers could leverage this feature to execute harmful code on victims’ computers without requiring any user interaction. This could potentially grant unauthorized access to sensitive information, activate cameras and microphones, or deploy malware across multiple platforms including Windows, macOS, Linux, Android, and iOS.
A Security’s lead researcher emphasized the significance of this discovery, noting that developing such exploits traditionally required extensive resources and expertise comparable to nation-state capabilities. The research team accomplished in a single day what would typically demand months of work and substantial government-level funding. Zoom released a patch addressing the vulnerability across all affected platforms on Tuesday.
