Zoom patches critical ‘Zoomsday’ vulnerability discovered via AI-assisted exploit
The vulnerability allowed attackers to hijack devices during meetings by targeting the annotation feature, enabling data theft and malware installation without user interaction.

Zoom has released a critical security patch for a major vulnerability that permitted attackers to hijack users’ devices during meetings. The flaw, identified by security researchers at A Security, allowed malicious code execution that could steal data, activate cameras or microphones, or install malware without any interaction from the victim or visual cues indicating a compromise.
The vulnerability, dubbed ‘Zoomsday’, targeted the application’s annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. By exploiting this function, an attacker joining or hosting a meeting could run code on victims’ devices, effectively taking control of the hardware.
A Security researchers discovered the flaw using fewer than 20 prompts on publicly available AI models. Idan Levcovich, a vulnerability researcher at A Security, noted in a blog post that producing a working exploit against such a high-level vulnerability has traditionally been considered nation-state work, requiring elite teams, months of effort, and significant budgets.
“A Security did it in a single day, with an AI agent and models anyone can access today,” Levcovich wrote. The discovery highlights the growing capability of artificial intelligence to accelerate the creation of complex cyber exploits using readily accessible tools.
Zoom issued the fix on Tuesday, applying the update across Windows, macOS, Linux, Android, and iOS versions of the application. The patch addresses the security gap that allowed for silent device hijacking, restoring protections that had been bypassed by the AI-assisted attack vector.

