Researcher Says Public AI Models Helped Build a Serious Zoom Exploit in Under a Day
A Security, an Israeli cybersecurity firm, said a researcher used publicly available AI models to identify flaws in Zoom’s annotation feature and assemble a working exploit in less than 24 hours. In a report published Tuesday and titled "Zoomsday," the firm said the researcher needed fewer than 20 prompts to uncover the issues. According to the report, the exploit could let someone in a Zoom meeting take control of another participant’s device without any action from the victim and without a visible sign that the system had been compromised. A Security said it tested the attack against Zoom apps on Windows, macOS, Linux, Android, and iOS. The vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. The firm said a compromised presenter could target every participant, while any participant could also target the presenter. Zoom told Decrypt that the issue has already been resolved, though A Security said users still need to update because a server-side safeguard could not block malicious messages in end-to-end encrypted meetings. The report arrives as AI tools are being used more often to find software bugs across the tech industry.








