ZOOM
AI found a nasty Zoom vulnerability
Zoom has fixed a major security flaw that could have let attackers take control of someone’s device during a meeting, without the victim clicking anything or seeing a warning.
Researchers at A Security said they found the flaw using fewer than 20 prompts with publicly available AI models.
The issue was linked to Zoom’s annotation feature, which lets people draw on a shared screen.
An attacker could potentially use it to run harmful code on another person’s device, access data, turn on their camera or microphone, or install malware.
In brief:
Attackers could potentially take control of a device through Zoom’s annotation tool.
Researchers say AI helped them build the attack much faster.
Zoom has now patched the issue across its main desktop and mobile apps.
Quite a lot of power for a digital Sharpie
A Security said this type of attack would usually take expert teams months to build.
Its researchers claim they created a working version in one day using an AI agent and widely available models.
Zoom released a fix on Tuesday for Windows, macOS, Linux, Android and iOS.
You dropped the ball hard, Zoom. - MV


