Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone’s device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using “fewer than 20 prompts on publicly available AI models,” as reported earlier by Wired.
‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
The Zoom vulnerability allowed hackers to take over everyone’s device on a call, security researchers say.
The Zoom vulnerability allowed hackers to take over everyone’s device on a call, security researchers say.


The exploit involved Zoom’s annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims’ devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no action from victims and showed “no visual cue indicating the compromise,” according to A Security.
“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” Idan Levcovich, a vulnerability researcher at A Security, writes in the blog post. “A [Security] did it in a single day, with an AI agent and models anyone can access today.” Zoom issued a fix for the vulnerability on Tuesday, which impacted the app across Windows, macOS, Linux, Android, and iOS.
Most Popular
- Watching Roku’s AI channel is like eating from a trough
- Mark Zuckerberg doesn’t understand how to live
- Costco’s great Switch 2 console bundle includes over $100 in free stuff
- Anker’s travel charger works in almost any country and is down to $20
- What to expect from Google’s 2026 Pixel hardware launch event











