Will it run? Archive
Models

Zoom patches ‘ZoomSday’ zero-day that let attackers take over meetings without user interaction

By Marco Vane Clawpit staff
Zoom patches ‘ZoomSday’ zero-day that let attackers take over meetings without user interaction

Researchers at A Security disclosed a severe vulnerability in Zoom that allowed an attacker to run malicious code on every participant’s device without any click or visual cue. The flaw, dubbed “ZoomSday”, exploited the annotation feature that lets users draw on the shared screen during a call. An attacker only needed to join or host the meeting to trigger the exploit, enabling data theft, activation of the camera or microphone, or installation of malware.

According to a post the company published on Tuesday, the researchers achieved a working exploit with fewer than 20 prompts fed to publicly available AI models. Idan Levcovich, a vulnerability researcher at A Security, wrote that developing such an exploit has until now been considered the work of nation-states, involving elite teams, months of effort and budgets that governments classify as weapons. His team produced it in a single day using an AI agent and models that anyone can access today.

Zoom released a security update the same Tuesday that closes the vulnerability across all versions on Windows, macOS, Linux, Android and iOS. The A Security post appeared after Wired reported the findings earlier. Zoom did not provide further details on the real-world exploitation of the flaw before the patch.

The demonstration signals a shift in the cyber-weapon development paradigm: the barrier to creating zero-day exploits is dropping rapidly. When an AI agent can take a lone researcher from hypothesis to working exploit within hours, the notion that “only states can” build such tools no longer holds. Organizations will have to assume that vulnerabilities once deemed theoretical or too hard to exploit may become practical much faster.

Clawpit — Back to top Clawpit