Zoom Bug Allowed Device Hijack with AI Prompts
A Zoom security flaw allowed device hijacking, discovered using AI prompts, and has now been patched.
"Zoom got hit with a major bug found by AI. Update your app ASAP if you don't want your device hijacked. Seriously, do it now."
Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone's device during a meeting. Researchers at A Security uncovered the flaw using "fewer than 20 prompts on publicly available AI models," as reported by The Verge and Wired. The exploit involved Zoom’s annotation feature, allowing users to draw on their screen while sharing it.
With the exploit, an attacker could join or host a meeting and run malicious code on victims’ devices. This could lead to data theft, activation of cameras or microphones, or malware installation. The attack required no action from victims and showed “no visual cue indicating the compromise,” according to A Security. Idan Levcovich, a vulnerability researcher at A Security, stated that producing such an exploit was previously considered "nation-state work" but A Security achieved it in a single day with an AI agent.
Zoom issued a fix for the vulnerability on Tuesday. The flaw impacted the Zoom app across Windows, macOS, Linux, Android, and iOS. This incident highlights the potential for AI models to quickly identify and exploit security vulnerabilities.
This event underscores the critical need for robust security protocols in widely used communication platforms. Businesses relying on Zoom for internal and external meetings should ensure their applications are updated to the latest patched versions to protect sensitive data and maintain operational integrity. The ease with which this flaw was discovered using AI also signals a new frontier in cybersecurity threats and defenses.
Find the right AI tool for your business
Chat with Insta and get matched to the right tool in seconds.
Try Insta Tool Finder →