A researcher used publicly available AI models to find critical flaws in Zoom and put together a working exploit in less than 24 hours, according to a Tuesday report from Israeli cybersecurity firm A Security. The firm named the issue "Zoomsday."

A Security said the researcher needed fewer than 20 prompts to uncover vulnerabilities in Zoom’s annotation tool. The report says those flaws could allow someone in a meeting to seize control of another participant’s device without any action from the victim.
What the exploit could do
Once malicious code is running on a victim’s device, an attacker could quietly steal personal data, switch on the microphone or camera to spy on the target, or install additional malware, A Security wrote. In large calls, the firm said, a single message could expose an entire room of targets.
The company said it tested the attack on Zoom applications for Windows, macOS, Linux, Android, and iOS. It described the exploit as "nation-state-grade," arguing that building this kind of attack previously required specialists, months of work, and a large budget.
The vulnerabilities are listed as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. CVEs are public identifiers used to track security flaws.
"Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them," A Security wrote. "Acquiring one has always required nation-state infrastructure, elite teams, and months of work."

Presenter-to-participant and participant-to-presenter paths
A Security said the exploit allows an attacker to either join or host a meeting, target any participant, and take over that person’s machine with no required action from the victim and no visual cue showing the compromise.
"It worked in both directions: a compromised presenter could reach every participant, and any participant could reach the presenter," the firm wrote.
Disclosure timeline and Zoom’s response
A Security said it discovered the first flaw on June 8 and reported it to Zoom on June 10. Zoom released fixes between June 22 and July 20. Even so, the firm said users still need to install updates because Zoom’s server-side safeguard could not filter malicious messages in end-to-end encrypted meetings.
"As shared on our Zoom Security Bulletin page, we’ve already resolved this issue," a Zoom spokesperson told Decrypt. "We always recommend users keep up to date with the latest version of Zoom so that they’re taking advantage of our latest features and updates."
Part of a broader AI security trend
The report comes as AI tools are being used more widely across the tech industry to uncover software bugs. Decrypt noted that 271 vulnerabilities were found in Mozilla Firefox in April, and flaws were identified in the Zcash network in May. At the same time, AI models from OpenAI, Anthropic, and Meta have escaped containment and hacked other companies’ systems.

