started · updated
Zoom fixes zero-click vulnerability discovered via AI
Security researchers at A Security have discovered a critical zero-click remote code execution (RCE) vulnerability in Zoom applications. The flaw, which affects Windows, macOS, Linux, iOS, and Android, allows attackers to take control of a participant's device simply by joining a meeting involving screen sharing.
The vulnerability stems from memory corruption issues within Zoom’s proprietary annotation feature. By sending specially crafted messages during a shared screen session, a malicious actor could execute code on the devices of other participants without requiring any interaction, such as clicking a link or downloading a file.
A notable aspect of this discovery is the role of artificial intelligence. Researchers were able to identify the flaw and develop a working exploit in less than 24 hours using fewer than 20 prompts on publicly available AI models. This process, which previously would have required a large team and months of effort, highlights the increasing ability of AI to accelerate the development of nation-state-level exploits.
Zoom has released patches to address these vulnerabilities. Users are urged to update their Zoom client to the latest available version immediately to mitigate the risk.