Tech

Zoom patches critical ‘Zoomsday’ vulnerability discovered via AI-assisted exploit

The vulnerability allowed attackers to hijack devices during meetings by targeting the annotation feature, enabling data theft and malware installation without user interaction.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: The Verge · View original source
‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
Security researchers at A Security uncovered the flaw using fewer than 20 prompts on public AI models, bypassing protections that previously required nation-state resources.

Zoom has released a critical security patch for a major vulnerability that permitted attackers to hijack users’ devices during meetings. The flaw, identified by security researchers at A Security, allowed malicious code execution that could steal data, activate cameras or microphones, or install malware without any interaction from the victim or visual cues indicating a compromise.

The vulnerability, dubbed ‘Zoomsday’, targeted the application’s annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. By exploiting this function, an attacker joining or hosting a meeting could run code on victims’ devices, effectively taking control of the hardware.

A Security researchers discovered the flaw using fewer than 20 prompts on publicly available AI models. Idan Levcovich, a vulnerability researcher at A Security, noted in a blog post that producing a working exploit against such a high-level vulnerability has traditionally been considered nation-state work, requiring elite teams, months of effort, and significant budgets.

“A Security did it in a single day, with an AI agent and models anyone can access today,” Levcovich wrote. The discovery highlights the growing capability of artificial intelligence to accelerate the creation of complex cyber exploits using readily accessible tools.

Zoom issued the fix on Tuesday, applying the update across Windows, macOS, Linux, Android, and iOS versions of the application. The patch addresses the security gap that allowed for silent device hijacking, restoring protections that had been bypassed by the AI-assisted attack vector.

Continue reading

More from Tech

Read next: XMPP Essay Says Visibility, Not Features, Is the Key to Growth
Read next: The world’s biggest IMAX theatre depends on how it is measured
Read next: USB-C has more audio potential, but the DAC matters more than the port