Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone’s device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using “fewer than 20 prompts on publicly available AI models,” as reported earlier by Wired.
The exploit involved Zoom’s annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims’ devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no action from victims and showed “no visual cue indicating the compromise,” according to A Security.
“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” Idan Levcovich, a vulnerability researcher at A Security, writes in the blog post. “A [Security] did it in a single day, with an AI agent and models anyone can access today.” Zoom issued a fix for the vulnerability on Tuesday, which impacted the app across Windows, macOS, Linux, Android, and iOS.
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

By The Verge | Created at 2026-08-11 18:05:22 | Updated at 2026-08-11 20:02:13
5 hours ago







