Zoom has patched a serious security vulnerability that could have allowed attackers to take control of devices belonging to people in a meeting.
Security researchers at A Security said they discovered the flaw using fewer than 20 prompts with publicly available AI models.
The vulnerability was connected to Zoom’s annotation feature, which allows meeting participants to draw or mark things on the screen while someone is sharing their display. Researchers found a way to abuse the feature to execute malicious code on other participants’ devices.
An attacker could join or host a Zoom meeting and exploit the vulnerability without requiring victims to click anything or take any other action. According to the researchers, a successful attack could allow hackers to steal data, activate a device’s camera or microphone, or install malware.
The attack could also be difficult for victims to notice because it reportedly did not display any obvious visual indication that their device had been compromised.
A Security vulnerability researcher Idan Levcovich said the ability to create a working exploit for a flaw of this type would traditionally require highly skilled teams, significant resources and months of effort. Researchers were instead able to develop the exploit in a single day with the help of an AI agent and publicly available AI models.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Zoom released a security fix on Tuesday addressing the vulnerability. The flaw affected the Zoom application across Windows, macOS, Linux, Android and iOS.





