Security researchers at A Security built a working Zoom exploit capable of hijacking every device on a call using fewer than 20 prompts on publicly available AI models, according to a blog post the firm published Tuesday. Zoom patched the flaw the same day, on August 11, 2026, and the fix covers Windows, macOS, Linux, Android, and iOS. The researchers, who nicknamed the bug 'Zoomsday,' say the entire exploit chain came together in a single day.
The attack targeted Zoom's annotation feature, the tool that lets meeting participants draw on a shared screen. By abusing it, an attacker who joined or hosted a meeting could run arbitrary code on other participants' devices, exfiltrate data, switch on cameras and microphones, or install malware. Victims had to do nothing for the attack to land, and A Security says there was 'no visual cue indicating the compromise' on screen while it happened.
What makes the disclosure notable is not the vulnerability itself but how it was found. A Security did not deploy a large in-house reverse-engineering team. It used off-the-shelf large language models, the same ones anyone with an account can access, and steered them through fewer than 20 prompts to identify the flaw and build a working proof of concept. That collapses a workflow that has historically required specialist security researchers into something closer to guided prompting.
Key facts
- 01Researchers at A Security built a working Zoom exploit using fewer than 20 prompts on publicly available AI models.
- 02The exploit abused Zoom's annotation feature to run malicious code on any device in a meeting, with no visual cue to the victim.
- 03The vulnerability affected Zoom on Windows, macOS, Linux, Android, and iOS; Zoom patched it Tuesday, August 11, 2026.
- 04A Security says the work took a single day, versus the months typically required by nation-state teams for comparable exploits.
Idan Levcovich, the A Security vulnerability researcher who authored the writeup, framed the shift in stark terms.
The economics that quote points at are the real story. Zoom is used by hundreds of millions of people for work meetings, medical appointments, court hearings, and government business. A pre-authentication, no-click remote code execution bug that touches every major operating system is exactly the class of vulnerability that intelligence agencies stockpile and that brokers pay seven-figure sums for. If a small commercial security shop can now produce one in a day with consumer AI tools, the supply curve for that kind of capability has changed shape.
Zoom's response was fast: the company shipped a patch on the same day the disclosure went live, and users on all five supported platforms should install the update. Auto-updates will catch most consumer installs, but enterprise deployments where IT controls the rollout are the ones worth watching, because those are also the environments where a hijacked meeting is most damaging.
The finding lands in the middle of a broader industry argument about whether AI tools help defenders or attackers more. A Security's case is that both sides get the same lift, but the offensive side benefits first because building one working exploit is a bounded problem, while defending an entire codebase is not. Zoom's engineers had to secure every code path in the annotation feature; the researchers only had to find one that broke.
There are reasons to be cautious about extrapolating from a single disclosure. A Security is a firm with an interest in publicizing dramatic results, 'fewer than 20 prompts' is a slippery metric that does not capture the human judgment guiding those prompts, and the researchers had a specific hypothesis about the annotation feature before they started. AI did not autonomously discover the bug from scratch; it accelerated researchers who knew where to look. The company also has not published the prompts themselves, which makes independent replication difficult.
Even with those caveats, the trend line is uncomfortable for every large software vendor. Vulnerability research budgets at big platform companies were sized against an era when bug discovery scaled roughly with headcount. If AI-assisted research keeps compressing the time from 'idea' to 'working exploit,' the mismatch between offense and defense widens, and patch-cycle timelines that assumed weeks of window may need to assume days. Zoom's same-day fix here is the benchmark other vendors will now be measured against, and few of them are currently set up to hit it.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




