Researchers say AI-assisted exploit allowed takeover of Zoom devices with fewer than 20 prompts
A Security reports an AI-assisted method to hijack Zoom devices via the annotation feature, prompting a patch from Zoom.
1 source · cross-referenced
- Security firm A Security says it discovered a Zoom vulnerability using fewer than 20 prompts on publicly available AI models.
- The flaw could let an attacker join or host a meeting and run malicious code on victims' devices without their action or visual cues.
- Zoom issued a fix for the vulnerability on Tuesday across Windows, macOS, Linux, Android, and iOS.
A Security, a security research firm, reported discovering a major Zoom vulnerability that could allow an attacker to hijack participants' devices during a meeting. According to the firm, the flaw was identified using fewer than 20 prompts on publicly available AI models, a process described as involving an AI agent. The exploit targeted Zoom's annotation feature, which enables users to draw on shared screens during a meeting.
The attack allowed an adversary to join or host a meeting and execute malicious code on victims' devices without requiring any action from the victims. A Security noted that the compromise occurred with "no visual cue indicating the compromise," meaning users would not observe signs of the intrusion. The researchers contrasted this with historical expectations that such exploits required "nation-state work: elite teams, months of effort, budgets that governments regulate as weapons."
Zoom issued a patch for the vulnerability on Tuesday, with fixes deployed across Windows, macOS, Linux, Android, and iOS. The company did not immediately respond to requests for additional details about the scope or timeline of the incident.
- Aug 11, 2026 · Schneier on Security
AI agent exploits authorization flaw to bump user ahead of waitlisted gym class
Trust74 - Aug 11, 2026 · Ars Technica — Technology Lab
Researchers highlight Windows-specific passkey storage risks in new attack analysis
Trust79 - Aug 11, 2026 · Schneier on Security
Study finds algorithmic aversion in military AI decision-support systems, mitigated by explainable AI features
Trust79