AI Prompts Uncover Critical Zoom Security Flaw
TL;DR. Researchers used under 20 AI prompts to find a critical Zoom security vulnerability, allowing attackers to hijack devices during calls. - The exploit, dubbed 'Zoomsday,' affected all major Zoom apps across Windows, macOS, Linux, Android, and iOS. - The flaw leveraged Zoom's annotation feature to run malicious code without victim interaction or visual cues. - A Security states such exploits previously required nation-state resources but were achieved in one day with AI agents.
- A Security researchers uncovered a critical Zoom vulnerability using fewer than 20 AI prompts.
- The 'Zoomsday' exploit allowed attackers to hijack devices during calls via Zoom's annotation feature.
- The attack required no user interaction and left no visual trace, impacting all major Zoom apps.
- This demonstrates how accessible AI tools can significantly lower the barrier for discovering sophisticated exploits.
Sources
- ‘Zoomsday’ hack uncovered using fewer than 20 AI prompts — theverge.com