Zoom has patched a critical security flaw that permitted attackers to hijack user devices during video calls. Researchers at A Security demonstrated the vulnerability using fewer than twenty prompts from publicly available AI models. The exploit targeted the platform’s annotation feature, which allows participants to draw on shared screens. By injecting malicious code through this function, an intruder could execute arbitrary commands on a victim’s machine without their consent. This access enabled the theft of sensitive data, activation of cameras and microphones, or installation of malware. The attack required no physical interaction with the target device, relying instead on the trust established within the meeting environment. Zoom confirmed the issue and released a security bulletin to address the gap immediately.
The significance lies in how artificial intelligence lowered the barrier for executing complex attacks. Previously, exploiting such a flaw would have demanded deep technical knowledge and custom tooling. Now, generic AI models can generate the necessary payloads with minimal human intervention. This shift suggests that many similar vulnerabilities in other software may be exploitable by less skilled actors using similar automated methods. The incident highlights the growing risk of AI-assisted cyber threats targeting enterprise communication tools.
* The vulnerability was identified via Zoom’s internal reporting channel.
* A Security published their findings on Tuesday.
* Zoom issued a patch to resolve the issue.




