Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

theverge+1a+1linkedin+1A cybersecurity firm used publicly available AI models to uncover a severe zero-click remote code execution flaw in Zoom that could have allowed an attacker to silently hijack any participant's device during a meeting. The vulnerability, dubbed "Zoomsday," was patched on Tuesday after researchers at A Security demonstrated they could identify and exploit the bug in under 24 hours using fewer than 20 AI prompts.
The vulnerability, tracked as CVE-2026-53413, resides in Zoom's annotation feature — the tool that lets participants draw and type on a shared screen during calls. Because Zoom's client automatically parses data received through the annotation protocol, an attacker could send a specially crafted oversized message to corrupt a recipient's memory and execute arbitrary code. The proprietary protocol opens a direct channel between a viewer and a sharer, letting the attacker target each participant individually.gbhackers+1
The exploit required no action from victims and produced "no visual cue indicating the compromise," according to A Security. In a proof-of-concept on macOS, a researcher silently launched Safari on a target system simply by joining the same meeting. The flaw affected every version of Zoom on Windows, macOS, Linux, iOS, and Android up to and including version 7.0.5.a+3
What makes the disclosure notable is how the vulnerability was found. "Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons," wrote Idan Levcovich, a vulnerability researcher at A Security. "A Security did it in a single day, with an AI agent and models anyone can access today."theverge
The researchers used publicly available frontier AI models to identify and exploit the closed, undocumented protocol — work that would traditionally require specialized reverse-engineering skills and weeks of labor. While the AI did the heavy lifting, A Security noted that experienced security researchers guided the process, directing the models on what to look for.gizmodo+2
Zoom released fixes on Tuesday in Workplace versions 7.1.5 and 7.0.6, Rooms version 7.1.5, and Meeting SDK version 7.1.5. Users must update manually to be protected.thehackernews+1
The disclosure arrives days after Black Hat USA 2026 in Las Vegas, where officials from the United States and United Kingdom warned that AI-driven vulnerability discovery is outpacing defenders' ability to patch. According to data presented at the conference, the average enterprise patch window grew 11 days longer in the first half of 2026, while attacker breakout time has dropped to under 30 minutes.linkedin+1