ASecurity says AI found exploitable Zoom annotation flaws in under 24 hours

ASecurity says AI found exploitable Zoom annotation flaws in under 24 hours

N
News Editor
2026-08-13 01:08:56
Israeli cybersecurity firm ASecurity said a researcher used publicly available AI models to identify multiple flaws in Zoom’s annotation tool and build an exploitable attack chain in less than 24 hours, using fewer than 20 prompts, according to Decrypt. The vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. ASecurity said the bugs could let an attacker remotely execute code during a meeting without any action from the victim. In the scenario described by the firm, an attacker could take control of the target device, steal data, or turn on the microphone or camera. The report said the attack was tested successfully across Zoom on Windows, macOS, Linux, Android, and iOS. ASecurity described the exploit chain as reaching a “nation-state” level and said building tools of this kind previously would have required a specialized team, months of work, and a large budget. The firm said it reported the first flaw to Zoom on June 10, and Zoom released patches between June 22 and July 20. A Zoom spokesperson said the issue has been resolved and advised users to stay on the latest version.

Israeli cybersecurity firm ASecurity said a researcher used publicly available AI models to find multiple vulnerabilities in Zoom’s annotation tool and assemble an exploitable attack chain in less than 24 hours with fewer than 20 prompts, according to Decrypt.

The flaws are listed as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. ASecurity said an attacker could use them to remotely execute code during a meeting without any action from the victim, then take control of the device, steal data, or activate the microphone or camera.

ASecurity said the attack was tested successfully on Zoom for Windows, macOS, Linux, Android, and iOS. The firm described the exploit as reaching a “nation-state” level, adding that building tools like this previously would have taken a specialized team, months of work, and a large budget.

ASecurity said it reported the first vulnerability to Zoom on June 10. Zoom rolled out fixes between June 22 and July 20. The report added that server-side protections in end-to-end encrypted meetings cannot filter malicious messages, so users need to update manually. A Zoom spokesperson confirmed the issue has been resolved and advised users to keep the software updated to the latest version.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
160

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.