Researchers used fewer than 20 AI prompts to build a Zoom exploit in 24 hours, enabling them to take over participants' devices
2026-08-12 17:58
Odaily Planet Daily News: Israeli cybersecurity firm A Security has disclosed that researchers, using publicly available AI models and fewer than 20 prompts, discovered vulnerabilities in the annotation tool of the video conferencing platform Zoom and built a working exploit within 24 hours.
The related vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. Attackers can join or host a meeting without requiring any victim action or visible prompts, then attack any participant and take over their device.
The attack has been tested across Zoom applications on Windows, macOS, Linux, Android, and iOS. Once an attacker gains control of a device, they can steal personal data, activate the microphone or camera, or install additional malware.
A Security reported the first vulnerability to Zoom on June 10, and Zoom issued fixes incrementally from June 22 to July 20. Because server-side protections in end-to-end encrypted meetings cannot filter malicious messages, users are still advised to update to the latest version. (Decrypt)
The related vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. Attackers can join or host a meeting without requiring any victim action or visible prompts, then attack any participant and take over their device.
The attack has been tested across Zoom applications on Windows, macOS, Linux, Android, and iOS. Once an attacker gains control of a device, they can steal personal data, activate the microphone or camera, or install additional malware.
A Security reported the first vulnerability to Zoom on June 10, and Zoom issued fixes incrementally from June 22 to July 20. Because server-side protections in end-to-end encrypted meetings cannot filter malicious messages, users are still advised to update to the latest version. (Decrypt)
