ZOOM

AI found a nasty Zoom vulnerability

Zoom has fixed a major security flaw that could have let attackers take control of someone’s device during a meeting, without the victim clicking anything or seeing a warning.

Researchers at A Security said they found the flaw using fewer than 20 prompts with publicly available AI models.

The issue was linked to Zoom’s annotation feature, which lets people draw on a shared screen.

An attacker could potentially use it to run harmful code on another person’s device, access data, turn on their camera or microphone, or install malware.

In brief:

  • Attackers could potentially take control of a device through Zoom’s annotation tool.

  • Researchers say AI helped them build the attack much faster.

  • Zoom has now patched the issue across its main desktop and mobile apps.

    Quite a lot of power for a digital Sharpie

A Security said this type of attack would usually take expert teams months to build.

Its researchers claim they created a working version in one day using an AI agent and widely available models.

Zoom released a fix on Tuesday for Windows, macOS, Linux, Android and iOS.

You dropped the ball hard, Zoom. - MV