Zoom AI Agent Vulnerable to Data Exfiltration
TL;DR. Zoom's AI chatbot, ZoomMate, has a critical vulnerability allowing attackers to exfiltrate meeting data via malicious AI Skills. - Attackers can establish command-and-control due to unrestricted network access in ZoomMate's coding environment. - Malicious Skills or prompt injections can manipulate the agent into connecting to attacker servers and issuing commands. - The attacker's connection persists even after the user stops the agent or closes Zoom.
- ZoomMate, Zoom's AI chatbot, has an agentic architecture with access to user data and connected services.
- The AI agent's environment lacks network restrictions, enabling attackers to establish persistent command-and-control.
- A malicious 'Skill' or prompt injection can force ZoomMate to connect to an attacker's server, allowing data exfiltration.
- The vulnerability allows attackers to steal meeting data, messages, and information from linked services like OneDrive and Google.
Sources
- Attacker Takes over Zoom AI — promptarmor.com