Zoom2026-08-12 17:58:35Researchers Built a Zoom Exploit in 24 Hours With Fewer Than 20 AI PromptsIsraeli cybersecurity firm A Security has disclosed that researchers used publicly available AI models to uncover vulnerabilities in Zoom's annotation tool and build a working exploit in under 24 hours, using fewer than 20 prompts. The three flaws—tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415—allow an attacker to join or host a meeting without any victim interaction or visible warning, then target any participant and take over their device. Tests covered Zoom's Windows, macOS, Linux, Android, and iOS apps. Once a device is compromised, an attacker can steal personal data, turn on the microphone or camera, or install additional malware. A Security first reported a vulnerability to Zoom on June 10; Zoom shipped fixes between June 22 and July 20. Because server-side protections can't filter malicious messages in end-to-end encrypted meetings, users are still advised to update to the latest version. Decrypt reported the research.1790