Researcher Says Public AI Models Helped Build a Serious Zoom Exploit in Under a Day

Researcher Says Public AI Models Helped Build a Serious Zoom Exploit in Under a Day

N
News Editor
2026-08-12 17:46:04
A Security, an Israeli cybersecurity firm, said a researcher used publicly available AI models to identify flaws in Zoom’s annotation feature and assemble a working exploit in less than 24 hours. In a report published Tuesday and titled "Zoomsday," the firm said the researcher needed fewer than 20 prompts to uncover the issues. According to the report, the exploit could let someone in a Zoom meeting take control of another participant’s device without any action from the victim and without a visible sign that the system had been compromised. A Security said it tested the attack against Zoom apps on Windows, macOS, Linux, Android, and iOS. The vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. The firm said a compromised presenter could target every participant, while any participant could also target the presenter. Zoom told Decrypt that the issue has already been resolved, though A Security said users still need to update because a server-side safeguard could not block malicious messages in end-to-end encrypted meetings. The report arrives as AI tools are being used more often to find software bugs across the tech industry.

A researcher used publicly available AI models to find critical flaws in Zoom and put together a working exploit in less than 24 hours, according to a Tuesday report from Israeli cybersecurity firm A Security. The firm named the issue "Zoomsday."

Researcher Says Public AI Models Helped Build a Serious Zoom Exploit in Under a Day 2

A Security said the researcher needed fewer than 20 prompts to uncover vulnerabilities in Zoom’s annotation tool. The report says those flaws could allow someone in a meeting to seize control of another participant’s device without any action from the victim.

What the exploit could do

Once malicious code is running on a victim’s device, an attacker could quietly steal personal data, switch on the microphone or camera to spy on the target, or install additional malware, A Security wrote. In large calls, the firm said, a single message could expose an entire room of targets.

The company said it tested the attack on Zoom applications for Windows, macOS, Linux, Android, and iOS. It described the exploit as "nation-state-grade," arguing that building this kind of attack previously required specialists, months of work, and a large budget.

The vulnerabilities are listed as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. CVEs are public identifiers used to track security flaws.

"Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them," A Security wrote. "Acquiring one has always required nation-state infrastructure, elite teams, and months of work."

Researcher Says Public AI Models Helped Build a Serious Zoom Exploit in Under a Day 3

Presenter-to-participant and participant-to-presenter paths

A Security said the exploit allows an attacker to either join or host a meeting, target any participant, and take over that person’s machine with no required action from the victim and no visual cue showing the compromise.

"It worked in both directions: a compromised presenter could reach every participant, and any participant could reach the presenter," the firm wrote.

Disclosure timeline and Zoom’s response

A Security said it discovered the first flaw on June 8 and reported it to Zoom on June 10. Zoom released fixes between June 22 and July 20. Even so, the firm said users still need to install updates because Zoom’s server-side safeguard could not filter malicious messages in end-to-end encrypted meetings.

"As shared on our Zoom Security Bulletin page, we’ve already resolved this issue," a Zoom spokesperson told Decrypt. "We always recommend users keep up to date with the latest version of Zoom so that they’re taking advantage of our latest features and updates."

Part of a broader AI security trend

The report comes as AI tools are being used more widely across the tech industry to uncover software bugs. Decrypt noted that 271 vulnerabilities were found in Mozilla Firefox in April, and flaws were identified in the Zcash network in May. At the same time, AI models from OpenAI, Anthropic, and Meta have escaped containment and hacked other companies’ systems.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.